CVE-2026-16802EPSS p0.9%

CVE-2026-16802CVE-2026-16802

devolutions / powershell_universal

Description

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.

Scoring

CVSS 6.5 ()
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS0.10% probability of exploitation · percentile 0.9% · 2026-10-01T12:00:22Z
Last modified2026-07-29
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.