PT-2026-25935 · Devolutions · Powershell Universal
Published
2026-03-17
·
Updated
2026-03-17
·
CVE-2026-4064
CVSS v3.1
8.3
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powershell Universal