Unrated severityNVD Advisory· Published Mar 17, 2026· Updated Mar 17, 2026
CVE-2026-4064
CVE-2026-4064
Description
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests.
Affected products
2- Range: <2026.1.4
- Devolutions/PowerShell Universalv5Range: 2026.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.