
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3563 is an improper input validation vulnerability in PowerShell Universal (by Ironman Software / Devolutions) affecting all versions before 2026.1.4. It allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes by specifying a conflicting URL path, resulting in unintended request routing and denial of service. The vulnerability was published on March 17, 2026, with a patch released shortly after. It carries a CVSS v3.1 base score of 5.5 (Medium) (Devolutions Advisory, Red Hat CVE).
The root cause is classified as CWE-1289 (Improper Validation of Unsafe Equivalence in Input), where the apps and endpoints configuration subsystem in PowerShell Universal fails to properly validate URL paths supplied by users when creating or modifying Apps or Endpoints. An authenticated attacker with the relevant administrative permissions can register a conflicting URL path that shadows or overrides an existing application or system route, causing legitimate requests to be routed to the attacker-controlled endpoint instead. Exploitation requires network access and high-privilege credentials (e.g., an account with App or Endpoint management rights), but no user interaction is needed (Devolutions Advisory, ENISA EUVD).
Successful exploitation can result in two primary consequences: unintended request routing, where legitimate user or system requests are silently misdirected to attacker-controlled endpoints (high integrity impact), and denial of service through route conflicts that disrupt normal application functionality (low availability impact). There is no confidentiality impact, as the vulnerability does not directly expose sensitive data. The scope is limited to the affected PowerShell Universal instance, but route hijacking could be leveraged to intercept or manipulate application logic within that environment (Devolutions Advisory, ENISA EUVD).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.032%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for an authenticated account with high-level permissions to manage Apps or Endpoints, significantly limiting the attacker pool (Devolutions Advisory, ENISA EUVD).
Upgrade PowerShell Universal to version 2026.1.4 or later, which contains the fix for this vulnerability. As an interim measure, restrict permissions to create or modify Apps and Endpoints to the minimum set of trusted administrators. Additionally, monitor and audit all changes to Apps and Endpoints configuration for unauthorized or suspicious modifications (Devolutions Advisory).
Coverage of CVE-2026-3563 has been limited to automated vulnerability tracking platforms and aggregators such as CVEFeed, VulDB, Wiz Vulnerability Database, and ENISA's EUVD. No notable independent researcher commentary or significant social media discussion has been identified. The vulnerability was assigned and disclosed by Devolutions, the vendor, with a straightforward advisory (Devolutions Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."