Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-16798

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 12.5%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-16798


Contact Us

Shodan ® - All rights reserved