Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows… (CVE-2026-92237)
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to the system log on instances backed by Microsoft SQL Server.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-92237) in Devolutions PowerShell Universal 2026.2.5 and earlier involves the slow query logging feature writing sensitive SQL parameter values into system log files. This exposure allows an authenticated user with permission to read logs to obtain sensitive credentials such as application tokens and data protection key material. The issue specifically affects instances using Microsoft SQL Server as the backend database.
Potential Impact
An authenticated user with log read permissions can access sensitive credentials including application tokens and data protection keys by reading SQL parameter values logged in system logs. This could lead to unauthorized access to protected resources or further compromise of the application environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict log read permissions to trusted users only and monitor access to logs containing sensitive information.
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows… (CVE-2026-92237)
Description
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to the system log on instances backed by Microsoft SQL Server.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-92237) in Devolutions PowerShell Universal 2026.2.5 and earlier involves the slow query logging feature writing sensitive SQL parameter values into system log files. This exposure allows an authenticated user with permission to read logs to obtain sensitive credentials such as application tokens and data protection key material. The issue specifically affects instances using Microsoft SQL Server as the backend database.
Potential Impact
An authenticated user with log read permissions can access sensitive credentials including application tokens and data protection keys by reading SQL parameter values logged in system logs. This could lead to unauthorized access to protected resources or further compromise of the application environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict log read permissions to trusted users only and monitor access to logs containing sensitive information.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wchh-mww7-897w
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-92237"]
- State
- PUBLISHED
Threat ID: 6aaa07d355bf5e2cf5ea26ed
Added to database: 09/16/2026, 03:06:59 UTC
Last enriched: 09/16/2026, 03:14:38 UTC
Last updated: 09/16/2026, 03:17:14 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.