Authorization Flaw in Devolutions Server Allows Unauthorized Vault Creation
CVE-2026-9223
4.3MEDIUM
What is CVE-2026-9223?
A security flaw in Devolutions Server permits low-privileged authenticated users to gain unauthorized access to create new vaults through a specially crafted import request. This vulnerability impacts the vault import feature found in versions 2026.1.16.0 and earlier, leading to potential data exposure if exploited.
Affected Version(s)
Server 0 <= 2026.1.16.0
