CVE-2026-13437: App tokens leaked via AI Agent job API in Devolutions PowerShell Universal
Devolutions PowerShell Universal 2026.2.0 serializes App Tokens in plaintext within AI Agent job API responses, allowing an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens.
Disclosed 29 June 2026 · Record updated 13 September 2026
Impact
Authenticated users with AI Agent read access could harvest reusable authentication tokens that may grant higher privileges than their own.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-13437
