CVE-2026-4064 PUBLISHED

Assigner: DEVOLUTIONS
Reserved: 12.03.2026 Published: 17.03.2026 Updated: 17.03.2026

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests.

Product Status

Vendor Devolutions
Product PowerShell Universal
Versions Default: unaffected
  • affected from 2026.1.0 to 2026.1.4 (excl.)

References

Problem Types

  • CWE-862 CWE