Server-Side Request Forgery Vulnerability in Devolutions Server by Devolutions
CVE-2026-90971

Currently unrated

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-90971?

A vulnerability exists within the VMware synchronization feature of Devolutions Server prior to version 2026.2.16, where a low-privileged authenticated user can exploit this flaw. By crafting a connection definition for datacenter discovery, the attacker is capable of accessing sensitive internal resources and cloud-metadata network endpoints. This poses significant risks, potentially leading to unauthorized access to other users' credentials and critical internal information.

Affected Version(s)

Server 0 <= 2026.2.16

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.