Sensitive Data Exposure in Devolutions Server by Devolutions
CVE-2026-100288

Currently unrated

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100288?

A vulnerability exists in Devolutions Server versions 2026.3.5.0 and earlier, where sensitive information, such as external identity provider tokens and active session identifiers, is stored in cleartext within the database. This design flaw permits unauthorized users with read access to the database to directly inspect the records, potentially leading to unauthorized access and exploitation of user sessions. Organizations utilizing affected versions are strongly advised to implement immediate measures to secure sensitive data and prevent unauthorized access.

Affected Version(s)

Server 0 < 2026.3.7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.