CVE Database
/

CVE-2026-3563

Back to search

CVE-2026-3563

Published: Mar 17, 2026

Modified: Mar 17, 2026

PUBLISHED

Description

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.

VendorProductVersions

Devolutions

PowerShell Universal

affected
2026.1.0 - < 2026.1.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now