5.3
CVE-2026-8694
- EPSS 0.22%
- Veröffentlicht 12.06.2026 14:11:33
- Zuletzt bearbeitet 15.06.2026 02:09:34
- Quelle security@devolutions.net
- CVE-Watchlists
- Unerledigt
Improper access control on the API documentation endpoint in PowerShell Universal
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ironmansoftware ≫ Powershell Universal Version < 2026.1.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.124 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
https://devolutions.net/security/advisories/DEVO-2026-0016/