CVE-2026-4064
CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations โ including reading sensitive data, creating or deleting resources, and disrupting service operations โ via crafted gRPC requests.
| CWE | CWE-862 |
| Vendor | devolutions |
| Product | powershell universal |
| Published | Mar 17, 2026 |
| Last Updated | Mar 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for devolutions powershell universal
Be the first to know when new high vulnerabilities affecting devolutions powershell universal are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Devolutions / PowerShell Universal
2026.1.0 < 2026.1.4