Ghostwire

CVE-2026-16799: Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and...

MEDIUM CVSS 0.0

Published: July 24, 2026 | Last Modified: July 24, 2026

Description

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References