Back to search
CVE-2026-4064
Published: Mar 17, 2026
Modified: Mar 17, 2026
PUBLISHED
Description
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests.
| Vendor | Product | Versions |
|---|---|---|
Devolutions | PowerShell Universal | affected 2026.1.0 - < 2026.1.4 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now