CVE-2026-92237: 
Ironman Software PowerShell Universal vulnerability analysis and mitigation

Overview

CVE-2026-92237 is a sensitive information disclosure vulnerability (CWE-532: Insertion of Sensitive Information into Log File) affecting Devolutions PowerShell Universal versions 2026.2.5 and earlier. The flaw resides in the slow query logging feature and exposes application tokens, data protection key material, and stored credentials via SQL parameter values written to system logs on instances backed by Microsoft SQL Server. It was published on September 15, 2026, with a patch made available the same day. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), requiring only low privileges and no user interaction to exploit (GitHub Advisory, Devolutions Advisory).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File). When the slow query logging feature is enabled on a PowerShell Universal instance backed by Microsoft SQL Server, SQL query parameters — which may contain application tokens, data protection key material, and other stored credentials — are written in plaintext to the system log. An authenticated user who holds log read permission can then access these logs and extract the sensitive values. No special exploitation technique beyond log access is required; the attacker simply reads the log entries containing the exposed SQL parameters (GitHub Advisory, Devolutions Advisory).

Impact

Successful exploitation allows an authenticated low-privileged user with log read access to obtain application tokens, data protection key material, and other stored credentials from system logs. This high-confidentiality impact could enable an attacker to escalate privileges, impersonate other users or services, decrypt protected data, or pivot laterally within the environment using the harvested credentials. Integrity and availability are not directly affected by this vulnerability (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.149% (0.371% per GitHub Advisory), placing it in the 29th percentile for exploitation likelihood within 30 days. Exploitation requires an authenticated account with log read permission, limiting the attacker pool, and the NVD SSVC assessment notes exploitation as "none" and the attack as non-automatable (GitHub Advisory).

Exploitation steps

  1. Gain authenticated access: Obtain credentials for a PowerShell Universal account that has log read permission on an instance backed by Microsoft SQL Server.
  2. Confirm slow query logging is enabled: Verify that the slow query logging feature is active in the PowerShell Universal configuration, as this is the prerequisite for sensitive data being written to logs.
  3. Access system logs: Navigate to the system log viewer within PowerShell Universal or access the underlying log storage directly (e.g., SQL Server tables or log files) using the authenticated account.
  4. Extract sensitive SQL parameters: Search log entries generated by the slow query logger for SQL parameter values, which may contain application tokens, data protection key material, and stored credentials in plaintext.
  5. Leverage harvested credentials: Use the extracted tokens or credentials to authenticate as other users or services, decrypt protected data, or move laterally within the environment (GitHub Advisory, Devolutions Advisory).

Indicators of compromise

  • Logs: Unusual or repeated access to system log entries by accounts that do not normally review logs; log entries containing SQL parameter values with token-like or key-like strings in the PowerShell Universal slow query log.
  • Authentication: Unexpected authentication events or API calls using application tokens shortly after a user with log read access was active, potentially indicating token reuse from harvested credentials.
  • Access Patterns: Low-privileged accounts querying or exporting system logs at unusual times or in bulk, particularly on SQL Server-backed PowerShell Universal instances with slow query logging enabled.

Mitigation and workarounds

Devolutions has released a patch addressing this vulnerability; users should update Devolutions PowerShell Universal to a version newer than 2026.2.5 as the primary remediation (Devolutions Advisory). As an interim workaround, disable the slow query logging feature on SQL Server-backed instances to prevent sensitive SQL parameters from being written to logs. Additionally, restrict log read permissions to only personnel who strictly require access, and review existing system logs for any unauthorized exposure of tokens or credentials (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Ironman Software PowerShell Universal vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16801HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-16800HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-19768HIGH8.1
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesAug 14, 2026
CVE-2026-92237MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoNoSep 15, 2026
CVE-2026-16802MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management