HarborGuard / CVE
Back to search
HIGHCVE-2026-4064Published Modified CNA DEVOLUTIONS

CVE-2026-4064: Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests.

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
2026.1.4
Affected Products
1

Fix available

2026.1.4
Affected packages
  • Devolutions / PowerShell Universal
    < 2026.1.4 (from 2026.1.0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
References