
Give an AI agent read-only access and it hands you back a working login token. Read-only was never read-only. CVE-2026-13437 landed on June 29 2026 in Devolutions PowerShell Universal 2026.2.0. The AI Agent job API leaked sensitive data into what it sent back. A user with nothing but AI Agent read access could pull reusable authentication tokens and replay them. [ WHAT ] sensitive data leaks through the AI Agent job API [ WHO ] any user with AI Agent read access [ PRIZE ] reusable auth tokens [ WHEN ] disclosed June 29 2026 Read access to an agent is not a small permission. It can be the whole keyring. Map what your agents can read before someone else does.
Post summary
The advisory reports CVE‑2026‑13437, a flaw in Devolutions PowerShell Universal 2026.2.0 that allows users with read‑only AI Agent access to retrieve and reuse authentication tokens, effectively bypassing intended permission limits.
