Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 17 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.
Weaknesses CWE-1289
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-03-17T20:04:00.419Z

Reserved: 2026-03-04T19:53:50.594Z

Link: CVE-2026-3563

cve-icon Vulnrichment

Updated: 2026-03-17T20:03:56.949Z

cve-icon NVD

Status : Received

Published: 2026-03-17T20:16:14.587

Modified: 2026-03-17T20:16:14.587

Link: CVE-2026-3563

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses