Improper Access Control in Devolutions Server Affects Sensitive Data Management
CVE-2026-93332

Currently unrated

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-93332?

The vulnerability in Devolutions Server allows low-privileged authenticated users to perform unauthorized actions on System Vault entries. By exploiting this flaw, users can read, create, modify, and delete sensitive data through crafted API requests. This poses a significant risk to data integrity and confidentiality, necessitating immediate attention from users of affected versions.

Affected Version(s)

Server 0 < 2026.3.7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.