CVE-2026-16800: 
Ironman Software PowerShell Universal vulnerability analysis and mitigation

Overview

CVE-2026-16800 is a code injection vulnerability (CWE-94) in the schedule feature of Devolutions PowerShell Universal that allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code. The flaw affects Devolutions PowerShell Universal version 2026.2.2 and earlier (all versions prior to 2026.2.3.0). It was published on July 24, 2026, with a patch available in version 2026.2.3. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Devolutions Advisory).

Technical details

The root cause is improper control of code generation (CWE-94): the schedule feature in PowerShell Universal concatenates user-supplied schedule parameter names directly into a PowerShell script invocation without adequate sanitization or neutralization. An authenticated attacker with schedule creation permissions can craft malicious parameter names containing PowerShell syntax that, when concatenated into the generated script, causes arbitrary code to execute. The attack vector is network-based, requires low privileges (schedule creation permission), no user interaction, and low attack complexity, making it straightforward to exploit once the attacker has the necessary access (GitHub Advisory, Devolutions Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary PowerShell code with the privileges of the PowerShell Universal service process, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker could exfiltrate sensitive data, modify or destroy system configurations, disrupt service availability, and potentially use the compromised service account for lateral movement within the environment (GitHub Advisory, Devolutions Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time (Feedly). The NVD SSVC assessment classifies exploitation as "none" and notes the attack is not automatable, as it requires an authenticated user with specific schedule creation permissions. The EPSS score is approximately 0.29% (22nd percentile), indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify a Devolutions PowerShell Universal instance running version 2026.2.2 or earlier. Confirm access to an account with schedule creation permissions.
  2. Authenticate: Log in to the PowerShell Universal web interface or API using valid credentials that include schedule creation rights.
  3. Create a malicious schedule: Navigate to the schedule creation feature and craft a schedule with a parameter name containing injected PowerShell code (e.g., a parameter name such as foo; Invoke-Expression 'malicious_command' or similar syntax that breaks out of the intended parameter context).
  4. Trigger execution: Save and activate the schedule. When PowerShell Universal processes the schedule, it concatenates the crafted parameter name into a script invocation, causing the injected PowerShell code to execute with the privileges of the service process.
  5. Achieve objective: Use the arbitrary code execution to establish persistence, exfiltrate data, or pivot to other systems within the environment (GitHub Advisory, Devolutions Advisory).

Indicators of compromise

  • Logs: PowerShell Universal audit logs showing schedule creation events by non-administrative users; unexpected PowerShell script executions triggered by scheduled jobs with unusual parameter names containing special characters (;, |, $, (, )).
  • File System: Unexpected files created by the PowerShell Universal service account (e.g., scripts, executables, or data files in temp directories); new or modified scheduled task definitions with anomalous parameter names.
  • Process: Unusual child processes spawned by the PowerShell Universal service (e.g., powershell.exe, cmd.exe, net.exe, curl.exe) performing network connections or file operations not consistent with normal automation workflows.
  • Network: Outbound connections from the PowerShell Universal server to unexpected external IP addresses or domains, particularly following schedule execution events.

Mitigation and workarounds

Devolutions has released a patched version: upgrade Devolutions PowerShell Universal to version 2026.2.3 or later to remediate this vulnerability (Devolutions Advisory). As an interim workaround, restrict schedule creation permissions to trusted administrators only, reducing the attack surface by limiting who can create or modify schedules. Additionally, review existing schedules for suspicious parameter names containing special characters that may indicate prior exploitation attempts.

Community reactions

The vulnerability received brief attention on social media, with mentions on Mastodon and Bluesky shortly after disclosure on July 24, 2026. No significant vendor statements beyond the official Devolutions security advisory or notable independent researcher commentary have been identified at this time (Feedly).

Additional resources


Source: This report was generated using AI

Related Ironman Software PowerShell Universal vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16801HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-16800HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-19768HIGH8.1
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesAug 14, 2026
CVE-2026-92237MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoNoSep 15, 2026
CVE-2026-16802MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management