HomeDefault status
unaffected
Any version
affected
Description
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
Any version
References
devolutions.net/security/advisories/DEVO-2026-0016/ (DEVO-2026-0016)