CVE-2026-8694
Improper access control on the API documentation endpoint in PowerShell Universal
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
| CWE | CWE-306 |
| Vendor | devolutions |
| Product | powershell universal |
| Published | Jun 12, 2026 |
| Last Updated | Jun 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for devolutions powershell universal
Be the first to know when new medium vulnerabilities affecting devolutions powershell universal are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Devolutions / PowerShell Universal
0 โค 2026.1.7