Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.
References
| Link | Resource |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0008 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-17 20:16
Updated : 2026-03-19 13:04
NVD link : CVE-2026-3563
Mitre link : CVE-2026-3563
CVE.ORG link : CVE-2026-3563
JSON object : View
Products Affected
ironmansoftware
- powershell_universal
CWE
CWE-1289
Improper Validation of Unsafe Equivalence in Input
