A vulnerability has been found in Devolutions PowerShell Universal up to 2026.2.2 and classified as very critical . Affected is an unknown function of the file variables configuration file of the component Variables Feature . The manipulation of the argument variable value leads to code injection. This vulnerability is documented as CVE-2026-16801 . The attack can be initiated remotely. There is not any exploit available. The affected component should be upgraded.