Server-Side Request Forgery Vulnerability in Devolutions Server
CVE-2026-4989
4.3MEDIUM
What is CVE-2026-4989?
The Devolutions Server is susceptible to an improper input validation vulnerability in its gateway health check feature. This flaw allows low-privileged authenticated users to leverage crafted API requests to execute server-side request forgery (SSRF). Consequently, this can lead to unauthorized access to sensitive information within the server, posing a significant security risk for affected installations.
Affected Version(s)
Server 2026.1.1 <= 2026.1.11
Server 2025.3.1 <= 2025.3.17
