LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-3563

ironmansoftware · powershell universal

Published
CVSS5.5
Severitymedium
WeaknessCWE-1289
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L

Description

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of service via a conflicting URL path.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-3563

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-3563.