VYPR
Medium severity5.3NVD Advisory· Published Jun 12, 2026· Updated Jun 12, 2026

CVE-2026-8694

CVE-2026-8694

Description

Devolutions PowerShell Universal 2026.1.7 and earlier exposes user-defined REST endpoint OpenAPI specs to unauthenticated remote attackers due to improper access control.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Devolutions PowerShell Universal 2026.1.7 and earlier exposes user-defined REST endpoint OpenAPI specs to unauthenticated remote attackers due to improper access control.

Vulnerability

An improper access control vulnerability exists in Devolutions PowerShell Universal versions 2026.1.7 and earlier [1]. The flaw allows an unauthenticated remote attacker to retrieve the OpenAPI specification of user-defined REST endpoints [1]. No authentication or special privileges are required to exploit this issue [1].

Exploitation

An unauthenticated attacker with network access to a vulnerable PowerShell Universal instance can request the OpenAPI specification for user-defined REST endpoints. The attacker does not need prior authentication or any other form of access [1]. The exact endpoint used to obtain the specification is not disclosed in the available references, but the advisory confirms that the operation is unauthenticated [1].

Impact

Successful exploitation discloses the OpenAPI specification of user-defined REST endpoints [1]. The OpenAPI specification may contain details about the API structure, parameters, request/response formats, and potentially sensitive information such as endpoint functionality or internal system details, aiding further attacks [1]. The disclosure does not directly lead to code execution or privilege escalation, but it increases the attack surface by providing an attacker with a detailed blueprint of the exposed API [1].

Mitigation

Devolutions has not yet released a patched version for PowerShell Universal as of the advisory publication date [1]. Users are advised to monitor the Devolutions security advisory page for updates and apply a fix once available. Restricting network access to the PowerShell Universal service and using firewall rules to limit exposure may reduce the risk [1].

References
  1. advisories

AI Insight generated on Jun 12, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.