CVE-2026-3563: 
Ironman Software PowerShell Universal vulnerability analysis and mitigation

Overview

CVE-2026-3563 is an improper input validation vulnerability in PowerShell Universal (by Ironman Software / Devolutions) affecting all versions before 2026.1.4. It allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes by specifying a conflicting URL path, resulting in unintended request routing and denial of service. The vulnerability was published on March 17, 2026, with a patch released shortly after. It carries a CVSS v3.1 base score of 5.5 (Medium) (Devolutions Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-1289 (Improper Validation of Unsafe Equivalence in Input), where the apps and endpoints configuration subsystem in PowerShell Universal fails to properly validate URL paths supplied by users when creating or modifying Apps or Endpoints. An authenticated attacker with the relevant administrative permissions can register a conflicting URL path that shadows or overrides an existing application or system route, causing legitimate requests to be routed to the attacker-controlled endpoint instead. Exploitation requires network access and high-privilege credentials (e.g., an account with App or Endpoint management rights), but no user interaction is needed (Devolutions Advisory, ENISA EUVD).

Impact

Successful exploitation can result in two primary consequences: unintended request routing, where legitimate user or system requests are silently misdirected to attacker-controlled endpoints (high integrity impact), and denial of service through route conflicts that disrupt normal application functionality (low availability impact). There is no confidentiality impact, as the vulnerability does not directly expose sensitive data. The scope is limited to the affected PowerShell Universal instance, but route hijacking could be leveraged to intercept or manipulate application logic within that environment (Devolutions Advisory, ENISA EUVD).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.032%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for an authenticated account with high-level permissions to manage Apps or Endpoints, significantly limiting the attacker pool (Devolutions Advisory, ENISA EUVD).

Exploitation steps

  1. Obtain privileged credentials: Acquire an account with permissions to create or modify Apps or Endpoints within the target PowerShell Universal instance (e.g., through credential theft, phishing, or insider access).
  2. Identify target routes: Enumerate existing application or system routes registered in the PowerShell Universal instance to identify high-value or critical endpoints to shadow.
  3. Create a conflicting App or Endpoint: Using the PowerShell Universal admin interface or API, create a new App or Endpoint configured with a URL path that matches or conflicts with an existing system or application route.
  4. Trigger route override: Once the conflicting route is registered, incoming requests to the targeted URL path are routed to the attacker-controlled endpoint instead of the legitimate one, enabling request interception or denial of service.
  5. Achieve objective: Depending on intent, the attacker can disrupt service availability (DoS) or manipulate application behavior by serving malicious responses to misdirected requests (Devolutions Advisory).

Indicators of compromise

  • Logs: Unexpected or duplicate route registrations appearing in PowerShell Universal application logs; audit log entries showing creation or modification of Apps/Endpoints by accounts not typically performing such actions.
  • Network: Legitimate application requests returning unexpected responses or being served by unrecognized handlers; unusual traffic patterns to previously stable application routes.
  • Application Configuration: New or modified Apps/Endpoints with URL paths that conflict with existing system routes; configuration changes made outside of normal change management windows.

Mitigation and workarounds

Upgrade PowerShell Universal to version 2026.1.4 or later, which contains the fix for this vulnerability. As an interim measure, restrict permissions to create or modify Apps and Endpoints to the minimum set of trusted administrators. Additionally, monitor and audit all changes to Apps and Endpoints configuration for unauthorized or suspicious modifications (Devolutions Advisory).

Community reactions

Coverage of CVE-2026-3563 has been limited to automated vulnerability tracking platforms and aggregators such as CVEFeed, VulDB, Wiz Vulnerability Database, and ENISA's EUVD. No notable independent researcher commentary or significant social media discussion has been identified. The vulnerability was assigned and disclosed by Devolutions, the vendor, with a straightforward advisory (Devolutions Advisory).

Additional resources


Source: This report was generated using AI

Related Ironman Software PowerShell Universal vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16801HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-16800HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-19768HIGH8.1
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesAug 14, 2026
CVE-2026-92237MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoNoSep 15, 2026
CVE-2026-16802MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management