CVE-2026-8694
Description
Devolutions PowerShell Universal 2026.1.7 and earlier exposes user-defined REST endpoint OpenAPI specs to unauthenticated remote attackers due to improper access control.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Devolutions PowerShell Universal 2026.1.7 and earlier exposes user-defined REST endpoint OpenAPI specs to unauthenticated remote attackers due to improper access control.
Vulnerability
An improper access control vulnerability exists in Devolutions PowerShell Universal versions 2026.1.7 and earlier [1]. The flaw allows an unauthenticated remote attacker to retrieve the OpenAPI specification of user-defined REST endpoints [1]. No authentication or special privileges are required to exploit this issue [1].
Exploitation
An unauthenticated attacker with network access to a vulnerable PowerShell Universal instance can request the OpenAPI specification for user-defined REST endpoints. The attacker does not need prior authentication or any other form of access [1]. The exact endpoint used to obtain the specification is not disclosed in the available references, but the advisory confirms that the operation is unauthenticated [1].
Impact
Successful exploitation discloses the OpenAPI specification of user-defined REST endpoints [1]. The OpenAPI specification may contain details about the API structure, parameters, request/response formats, and potentially sensitive information such as endpoint functionality or internal system details, aiding further attacks [1]. The disclosure does not directly lead to code execution or privilege escalation, but it increases the attack surface by providing an attacker with a detailed blueprint of the exposed API [1].
Mitigation
Devolutions has not yet released a patched version for PowerShell Universal as of the advisory publication date [1]. Users are advised to monitor the Devolutions security advisory page for updates and apply a fix once available. Restricting network access to the PowerShell Universal service and using firewall rules to limit exposure may reduce the risk [1].
AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2026.1.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.