Improper Access Control in Devolutions Server Affects Documentation Vaults
CVE-2026-6706

Currently unrated

Key Information:

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-6706?

The vulnerability in Devolutions Server allows authenticated attackers to exploit improper access control within the vault documentation feature. By crafting specific API requests, attackers can gain unauthorized access to sensitive documentation content stored in restricted vaults. This flaw could potentially lead to significant information exposure and compromise the confidentiality of sensitive data.

Affected Version(s)

Server 0 <= 2026.1.14.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.