---
id: CVE-2026-13437
title: >-
  Insertion of sensitive information into sent data in the AI Agent job API in
  Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI
  Agent read access to obtain reusable, potentially higher-privileged
  authenticatio…
summary: >-
  Insertion of sensitive information into sent data in the AI Agent job API in
  Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI
  Agent read access to obtain reusable, potentially higher-privileged
  authenticatio…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-201
vendor: devolutions
product: powershell_universal
affected:
  - powershell_universal = 2026.2.0.0
published: '2026-06-29'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13437'
references:
  - url: 'https://devolutions.net/security/advisories/DEVO-2026-0022/'
    label: security@devolutions.net
tags:
  - nvd
epss: 0.00438
epssPercentile: 0.35396
ingestedAt: '2026-07-03T13:02:28.092Z'
---

## Overview

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.

## Affected

- `powershell_universal = 2026.2.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
