By vendor
Ironmansoftware vulnerabilities
Known CVEs affecting Ironmansoftware products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-8694MEDIUM 5.3
Devolutions PowerShell Universal versions up to 2026.1.7 contain an access control flaw that allows anyone on the network to read the OpenAPI specification files for REST endpoints you've created. These specification files can reveal sensitive details about your API structure, parameters, and authentication methods—information that normally should only be available to authenticated users. An attacker doesn't need valid credentials to exploit this; they simply request the specification and receive it.