Security & compliance
Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0004
Devolutions Server is affected by multiple vulnerabilities.
Affected Products
Change Log
Initial publication - 2026-02-24
7.6 High - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Authorization bypass via permission cache poisoning
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.
Affected Products
CVE(s)
CVE-2026-1768
Remediation and Workarounds
Upgrade to DVLS 2025.3.15
Credits
JaGoTu, DCIT a.s.
8.5 High - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Sensitive credential exposure via /api/connections endpoints for view-only users
Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data through requests to the /api/connections/{id} endpoints.
Affected Products
CVE(s)
CVE-2026-3131
Remediation and Workarounds
Upgrade to DVLS 2025.3.15
5.9 Medium - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Cleartext storage of sensitive information in the database
Sensitive data in the user account database table including security keys and personal credentials was stored unencrypted in the database.
Affected Products
CVE(s)
CVE-2026-3221
Remediation and Workarounds
Upgrade to DVLS 2025.3.15