CVE-2026-19768
published 2026-08-14CVE-2026-19768: Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an…
PriorityP353high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.28%
19.9th percentile
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devolutions | powershell_universal | < 2026.2.4 | 2026.2.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permiss
ghsa_unreviewed·2026-08-14
CVE-2026-19768 [HIGH] CWE-94 Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permiss
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
GHSA
Weblate SSRF: outbound URL guard misses some private ranges
ghsa·2026-07-07
CVE-2026-50127 [MEDIUM] CWE-918 Weblate SSRF: outbound URL guard misses some private ranges
Weblate SSRF: outbound URL guard misses some private ranges
### Impact
Weblate's `VCS_RESTRICT_PRIVATE` did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.
### Patches
* https://github.com/WeblateOrg/weblate/pull/19768
### Resources
The issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-14
Published