Server-Side Request Forgery Vulnerability in Devolutions Server by Devolutions
CVE-2026-90971
Currently unrated
What is CVE-2026-90971?
A vulnerability exists within the VMware synchronization feature of Devolutions Server prior to version 2026.2.16, where a low-privileged authenticated user can exploit this flaw. By crafting a connection definition for datacenter discovery, the attacker is capable of accessing sensitive internal resources and cloud-metadata network endpoints. This poses significant risks, potentially leading to unauthorized access to other users' credentials and critical internal information.
Affected Version(s)
Server 0 <= 2026.2.16
