Authorization Flaw in Devolutions Server Network Scan API
CVE-2026-100289

Currently unrated

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100289?

A significant vulnerability exists in the gateway network scan token API of Devolutions Server, specifically in versions 2026.3.5.0 and earlier. This flaw permits authenticated low-privileged users to generate a network scan token. By crafting specific API requests, these users can conduct unauthorized internal network discovery and port scanning, potentially exposing sensitive information and network configurations.

Affected Version(s)

Server 0 < 2026.3.7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.