CVE-2026-16802: 
Ironman Software PowerShell Universal vulnerability analysis and mitigation

Overview

CVE-2026-16802 is a cleartext storage of sensitive information vulnerability (CWE-312) in Devolutions PowerShell Universal that allows a local actor with file system access to read secret values stored unencrypted on disk. The flaw affects Devolutions PowerShell Universal versions 2026.2.2 and earlier when no vault is configured for secret variable storage. It was published on July 24, 2026, with a patch available in version 2026.2.3. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Devolutions Advisory).

Technical details

The root cause is improper handling of secret variables in the variables feature of Devolutions PowerShell Universal, classified as CWE-312 (Cleartext Storage of Sensitive Information). When no vault is selected, secret variables are written to disk in plaintext rather than being encrypted, making them readable by any local user or process with access to the PowerShell Universal configuration directories. Exploitation requires low privileges and local file system access — no network access or user interaction is needed. The attack maps to CAPEC-37 (Retrieve Embedded Sensitive Data) and MITRE ATT&CK technique T1552.004 (Unsecured Credentials: Private Keys) (GitHub Advisory, Devolutions Advisory).

Impact

Successful exploitation results in full disclosure of secret variable values — such as credentials, API keys, or tokens — stored by PowerShell Universal on the local file system. The confidentiality impact is rated High with a changed scope, meaning secrets belonging to other components or systems (beyond the PowerShell Universal process itself) may be exposed. There is no integrity or availability impact, but exposed credentials could enable lateral movement or privilege escalation within the broader environment (GitHub Advisory, Devolutions Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Devolutions Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.076%, indicating a low near-term probability of exploitation. Exploitation is limited to local actors with file system access, reducing the overall attack surface compared to remotely exploitable vulnerabilities.

Exploitation steps

  1. Gain local access: Obtain a local user account or shell on the system running Devolutions PowerShell Universal, with at least low-privilege file system access to the application's configuration directories.
  2. Locate configuration files: Navigate to the PowerShell Universal data/configuration directory (typically under the application's installation or data path) and identify files storing variable definitions.
  3. Identify secret variables: Search configuration files for entries corresponding to secret variables — these will be stored in plaintext when no vault has been configured.
  4. Extract secrets: Read the plaintext secret values directly from the configuration files using standard file read operations (e.g., cat, type, or a text editor), obtaining credentials, API keys, or other sensitive data.
  5. Leverage extracted secrets: Use the recovered credentials or tokens to authenticate to downstream systems, escalate privileges, or move laterally within the environment (GitHub Advisory, Devolutions Advisory).

Indicators of compromise

  • File System: Unexpected access or modification timestamps on PowerShell Universal configuration files containing variable definitions; presence of scripts or tools in user directories designed to parse configuration files.
  • Logs: Operating system audit logs (e.g., Windows Security Event Log) showing file read access to PowerShell Universal configuration directories by non-administrative or unexpected user accounts.
  • Process: Unusual processes (e.g., cmd.exe, powershell.exe, text editors) accessing PowerShell Universal data directories under non-administrative user contexts.

Mitigation and workarounds

Devolutions has released a fix in PowerShell Universal version 2026.2.3; upgrading to this version or later is the primary recommended remediation (Devolutions Advisory). As a configuration-based workaround, administrators should configure a vault for secret storage so that secrets are not written to disk in cleartext. Additionally, file system access to PowerShell Universal configuration directories should be restricted to authorized administrators only. Existing secret variables should be audited to identify any stored in cleartext and migrated to a secure vault.

Additional resources


Source: This report was generated using AI

Related Ironman Software PowerShell Universal vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16801HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-16800HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-19768HIGH8.1
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesAug 14, 2026
CVE-2026-92237MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoNoSep 15, 2026
CVE-2026-16802MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management