CVE-2026-3563

EUVD-2026-12636
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
DEVOLUTIONSCNA
5.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
ironmansoftwarepowershell_universal
𝑥
< 2026.1.4
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
devolutionspowershell_universal
2026.1.0 ≤
𝑥
< 2026.1.4
CNA