No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0025/ |
|
Mon, 27 Jul 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Information Disclosure of OAuth Refresh Tokens in Devolutions PowerShell Universal |
Sat, 25 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 24 Jul 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions powershell Universal |
|
| Vendors & Products |
Devolutions
Devolutions powershell Universal |
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. | |
| Weaknesses | CWE-201 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-07-24T17:49:40.208Z
Reserved: 2026-07-23T19:24:47.342Z
Link: CVE-2026-16798
Updated: 2026-07-24T17:48:52.642Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T06:30:10Z