Vulnerability  ·  2026-06-30

Devolutions PowerShell Universal — AI Agent Job API Leaks Reusable App Tokens in Plaintext

VulnerabilityMedium impactGlobalCVE-2026-13437
Devolutions PowerShell Universal 2026.2.0 serializes App Tokens in plaintext inside AI Agent job API responses. An authenticated user with only 'AI Agent read' access can call the job API and extract App Tokens belonging to higher-privileged identities. These tokens are reusable and may carry significantly elevated permissions, enabling privilege escalation from AI Agent reader to broader platform administrator.
PowerShell Universal is used by enterprises to build and automate IT workflows, including AI Agent integrations. The plaintext token leakage means that an attacker with minimal AI Agent read access can escalate to full platform control by harvesting reusable admin-level tokens from job API responses, then using those tokens to modify scripts, environments, schedules, and security settings.
Authenticated user with 'AI Agent read' access calls the AI Agent job API endpoint; the response contains serialized App Tokens in plaintext that belong to higher-privileged identities. Attacker reuses the harvested tokens for privilege escalation.
Devolutions PowerShell Universal 2026.2.0
Apply vendor patch per Devolutions advisory DEVO-2026-0022: https://devolutions.net/security/advisories/DEVO-2026-0022/
Sources
Devolutions Security Advisory DEVO-2026-0022NVD CVE-2026-13437
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →