Description
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.
Published:
2026-07-24
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0025/ |
|
History
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. | |
| Weaknesses | CWE-201 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-07-24T17:49:40.208Z
Reserved: 2026-07-23T19:24:47.342Z
Link: CVE-2026-16798
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses