Improper Access Control in Devolutions Server by Devolutions
CVE-2026-90969
Currently unrated
What is CVE-2026-90969?
An improper access control vulnerability in the vault entry listing feature of Devolutions Server versions up to 2026.2.16 has been identified. This flaw allows authenticated users lacking the necessary view-password permission to exploit the entry listing endpoint, potentially disclosing cleartext passwords by using specific password disclosure parameters. This presents a significant security risk, as sensitive information can be accessed inappropriately.
Affected Version(s)
Server 0 <= 2026.2.16
