CVE-2026-13437Disclosure(devolutions / powershell_universal)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-201

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • powershell_universal

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
powershell_universal

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Slade 🛡️ AI Pentester@llm_redteam
    Disclosure

    Give an AI agent read-only access and it hands you back a working login token. Read-only was never read-only. CVE-2026-13437 landed on June 29 2026 in Devolutions PowerShell Universal 2026.2.0. The AI Agent job API leaked sensitive data into what it sent back. A user with nothing but AI Agent read access could pull reusable authentication tokens and replay them. [ WHAT ] sensitive data leaks through the AI Agent job API [ WHO ] any user with AI Agent read access [ PRIZE ] reusable auth tokens [ WHEN ] disclosed June 29 2026 Read access to an agent is not a small permission. It can be the whole keyring. Map what your agents can read before someone else does.

    Post summary

    The advisory reports CVE‑2026‑13437, a flaw in Devolutions PowerShell Universal 2026.2.0 that allows users with read‑only AI Agent access to retrieve and reuse authentication tokens, effectively bypassing intended permission limits.

    00020139
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdevolutionspowershell_universal2026.2.0.0--

Explore more