Improper Access Control in Devolutions Server by Devolutions
CVE-2026-90969

Currently unrated

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-90969?

An improper access control vulnerability in the vault entry listing feature of Devolutions Server versions up to 2026.2.16 has been identified. This flaw allows authenticated users lacking the necessary view-password permission to exploit the entry listing endpoint, potentially disclosing cleartext passwords by using specific password disclosure parameters. This presents a significant security risk, as sensitive information can be accessed inappropriately.

Affected Version(s)

Server 0 <= 2026.2.16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.