Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-16800

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 21.0%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-16800


Contact Us

Shodan ® - All rights reserved