
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16802 is a cleartext storage of sensitive information vulnerability (CWE-312) in Devolutions PowerShell Universal that allows a local actor with file system access to read secret values stored unencrypted on disk. The flaw affects Devolutions PowerShell Universal versions 2026.2.2 and earlier when no vault is configured for secret variable storage. It was published on July 24, 2026, with a patch available in version 2026.2.3. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Devolutions Advisory).
The root cause is improper handling of secret variables in the variables feature of Devolutions PowerShell Universal, classified as CWE-312 (Cleartext Storage of Sensitive Information). When no vault is selected, secret variables are written to disk in plaintext rather than being encrypted, making them readable by any local user or process with access to the PowerShell Universal configuration directories. Exploitation requires low privileges and local file system access — no network access or user interaction is needed. The attack maps to CAPEC-37 (Retrieve Embedded Sensitive Data) and MITRE ATT&CK technique T1552.004 (Unsecured Credentials: Private Keys) (GitHub Advisory, Devolutions Advisory).
Successful exploitation results in full disclosure of secret variable values — such as credentials, API keys, or tokens — stored by PowerShell Universal on the local file system. The confidentiality impact is rated High with a changed scope, meaning secrets belonging to other components or systems (beyond the PowerShell Universal process itself) may be exposed. There is no integrity or availability impact, but exposed credentials could enable lateral movement or privilege escalation within the broader environment (GitHub Advisory, Devolutions Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Devolutions Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.076%, indicating a low near-term probability of exploitation. Exploitation is limited to local actors with file system access, reducing the overall attack surface compared to remotely exploitable vulnerabilities.
cat, type, or a text editor), obtaining credentials, API keys, or other sensitive data.cmd.exe, powershell.exe, text editors) accessing PowerShell Universal data directories under non-administrative user contexts.Devolutions has released a fix in PowerShell Universal version 2026.2.3; upgrading to this version or later is the primary recommended remediation (Devolutions Advisory). As a configuration-based workaround, administrators should configure a vault for secret storage so that secrets are not written to disk in cleartext. Additionally, file system access to PowerShell Universal configuration directories should be restricted to authorized administrators only. Existing secret variables should be audited to identify any stored in cleartext and migrated to a secure vault.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."