Devolutions PowerShell Universal Authenticated Code Injection Enables Full Server Compromise (CVE-2026-16801)
Scope: Devolutions PowerShell Universal Versions 2026.2.2 and Earlier
Severity: High
Devolutions published advisory DEVO-2026-0025 on July 24, 2026, addressing two code injection vulnerabilities in PowerShell Universal, an IT automation platform widely used by system administrators and IT operations teams: CVE-2026-16801 in the variables feature and a companion flaw in the schedule feature (CVE-2026-16800), both rated CVSS 8.8. In CVE-2026-16801, the platform fails to properly escape user-supplied values when writing them to the variables configuration file, allowing any authenticated user with variable write permission to inject arbitrary PowerShell code that executes with the privileges of the PowerShell Universal service account, typically a high-privilege account on Windows Server environments. Given that PowerShell Universal service accounts are often granted broad administrative permissions to enable automation workflows, successful exploitation grants an attacker complete control over the host server, enabling data exfiltration, lateral movement, and persistent backdoor access. Organizations must upgrade to PowerShell Universal version 2026.2.3 immediately, audit existing variable and schedule configurations for unexpectedly crafted values, and review service account privilege levels as a defense-in-depth measure.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.