Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0028/ |
|
History
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary PowerShell Code Execution via Unescaped Settings in PowerShell Universal | |
| First Time appeared |
Devolutions
Devolutions powershell Universal |
|
| Vendors & Products |
Devolutions
Devolutions powershell Universal |
Fri, 14 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 14 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file. | |
| Weaknesses | CWE-94 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-08-14T14:52:35.426Z
Reserved: 2026-08-13T17:10:37.762Z
Link: CVE-2026-19768
Updated: 2026-08-14T14:52:26.083Z
Status : Received
Published: 2026-08-14T14:16:50.473
Modified: 2026-08-14T15:17:08.280
Link: CVE-2026-19768
No data.
OpenCVE Enrichment
Updated: 2026-08-14T15:30:03Z