CVE-2026-16799
Low
No strong exploitation signal.
CVSS base
5.0
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
EPSS — probability of exploitation (30 days)
0.2%
4.8th percentile
CISA KEV
Not listed
Weakness / dates
CWE-862
Published 2026-07-24 · modified 2026-07-29
CVSS breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | C | Changed |
| Confidentiality | N | None |
| Integrity | L | Low |
| Availability | N | None |
Timeline
- 2026-07-24 — Published (NVD)
- 2026-07-29 — Last modified (NVD)
Description
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.