
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-92237 is a sensitive information disclosure vulnerability (CWE-532: Insertion of Sensitive Information into Log File) affecting Devolutions PowerShell Universal versions 2026.2.5 and earlier. The flaw resides in the slow query logging feature and exposes application tokens, data protection key material, and stored credentials via SQL parameter values written to system logs on instances backed by Microsoft SQL Server. It was published on September 15, 2026, with a patch made available the same day. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), requiring only low privileges and no user interaction to exploit (GitHub Advisory, Devolutions Advisory).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File). When the slow query logging feature is enabled on a PowerShell Universal instance backed by Microsoft SQL Server, SQL query parameters — which may contain application tokens, data protection key material, and other stored credentials — are written in plaintext to the system log. An authenticated user who holds log read permission can then access these logs and extract the sensitive values. No special exploitation technique beyond log access is required; the attacker simply reads the log entries containing the exposed SQL parameters (GitHub Advisory, Devolutions Advisory).
Successful exploitation allows an authenticated low-privileged user with log read access to obtain application tokens, data protection key material, and other stored credentials from system logs. This high-confidentiality impact could enable an attacker to escalate privileges, impersonate other users or services, decrypt protected data, or pivot laterally within the environment using the harvested credentials. Integrity and availability are not directly affected by this vulnerability (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.149% (0.371% per GitHub Advisory), placing it in the 29th percentile for exploitation likelihood within 30 days. Exploitation requires an authenticated account with log read permission, limiting the attacker pool, and the NVD SSVC assessment notes exploitation as "none" and the attack as non-automatable (GitHub Advisory).
Devolutions has released a patch addressing this vulnerability; users should update Devolutions PowerShell Universal to a version newer than 2026.2.5 as the primary remediation (Devolutions Advisory). As an interim workaround, disable the slow query logging feature on SQL Server-backed instances to prevent sensitive SQL parameters from being written to logs. Additionally, restrict log read permissions to only personnel who strictly require access, and review existing system logs for any unauthorized exposure of tokens or credentials (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."