Medium severity6.5NVD Advisory· Published Feb 27, 2026· Updated Jun 17, 2026
CVE-2026-3277
CVE-2026-3277
Description
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <2026.1.3
- cpe:2.3:a:ironmansoftware:powershell_universal:*:*:*:*:*:*:*:*Range: <2026.1.3
- Range: 0
Patches
Vulnerability mechanics
References
1- devolutions.net/security/advisories/DEVO-2026-0006nvdThird Party Advisory
News mentions
0No linked articles in our index yet.