Authorization Flaw in Devolutions Server Network Scan API
CVE-2026-100289
Currently unrated
What is CVE-2026-100289?
A significant vulnerability exists in the gateway network scan token API of Devolutions Server, specifically in versions 2026.3.5.0 and earlier. This flaw permits authenticated low-privileged users to generate a network scan token. By crafting specific API requests, these users can conduct unauthorized internal network discovery and port scanning, potentially exposing sensitive information and network configurations.
Affected Version(s)
Server 0 < 2026.3.7.0
