Sensitive Data Exposure in Devolutions Server by Devolutions
CVE-2026-100288
Currently unrated
What is CVE-2026-100288?
A vulnerability exists in Devolutions Server versions 2026.3.5.0 and earlier, where sensitive information, such as external identity provider tokens and active session identifiers, is stored in cleartext within the database. This design flaw permits unauthorized users with read access to the database to directly inspect the records, potentially leading to unauthorized access and exploitation of user sessions. Organizations utilizing affected versions are strongly advised to implement immediate measures to secure sensitive data and prevent unauthorized access.
Affected Version(s)
Server 0 < 2026.3.7.0
