Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2026-0011
Devolutions Server is affected by an improper access control vulnerability.
Affected Products
Change Log
Initial publication - 2026-04-28
4.3 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Improper access control on documentation endpoints
Improper access control in the vault documentation feature in Devolutions Server 2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.
Affected Products
CVE(s)
CVE-2026-6706
Remediation and Workarounds
Upgrade to Devolutions Server 2026.1.15.0 or higher.
Credits
Supr4s