Server-Side Request Forgery Vulnerability in Devolutions Server
CVE-2026-4989

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-4989?

The Devolutions Server is susceptible to an improper input validation vulnerability in its gateway health check feature. This flaw allows low-privileged authenticated users to leverage crafted API requests to execute server-side request forgery (SSRF). Consequently, this can lead to unauthorized access to sensitive information within the server, posing a significant security risk for affected installations.

Affected Version(s)

Server 2026.1.1 <= 2026.1.11

Server 2025.3.1 <= 2025.3.17

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.