Improper Access Control in Devolutions Server Affects Documentation Vaults
CVE-2026-6706

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-6706?

The vulnerability in Devolutions Server allows authenticated attackers to exploit improper access control within the vault documentation feature. By crafting specific API requests, attackers can gain unauthorized access to sensitive documentation content stored in restricted vaults. This flaw could potentially lead to significant information exposure and compromise the confidentiality of sensitive data.

Affected Version(s)

Server 2026.1.6.0 <= 2026.1.14.0

Server 0 <= 2025.3.18.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.