CVE-2026-16802

Summary

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.

Affected Software

VendorProductVersion RangeStatus
DevolutionsPowerShell Universal0 < 2026.2.3affected

Weaknesses

  • CWE-312: CWE-312 Cleartext storage of sensitive information

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References