6.5
CVE-2026-13437
- EPSS 0.26%
- Veröffentlicht 29.06.2026 16:16:35
- Zuletzt bearbeitet 02.07.2026 15:09:07
- CVE-Watchlists
- Unerledigt
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Devolutions ≫ Powershell Universal Version2026.2.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.168 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-201 Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
https://devolutions.net/security/advisories/DEVO-2026-0022/