VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-13437

CVE-2026-13437: Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 a

Published Jun 29, 2026 CVSS 6.5

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.

Affected AI Products

ai agent
Get the weekly digest. Every Monday: top AI security stories of the week. Free.