CVE-2026-3277
EUVD-2026-903027.02.2026, 16:16
The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentialsEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ironmansoftware | powershell_universal | 𝑥 < 2026.1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration