MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0004

Devolutions Server is affected by multiple vulnerabilities.

Affected Products

Devolutions Server
2025.3.14 and earlier

Change Log

Initial publication - 2026-02-24

7.6 High - CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Authorization bypass via permission cache poisoning

A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.

Affected Products

CVE(s)

CVE-2026-1768

Remediation and Workarounds

Upgrade to DVLS 2025.3.15

Credits

JaGoTu, DCIT a.s.

8.5 High - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H

Sensitive credential exposure via /api/connections endpoints for view-only users

Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data through requests to the /api/connections/{id} endpoints.

Affected Products

CVE(s)

CVE-2026-3131

Remediation and Workarounds

Upgrade to DVLS 2025.3.15

5.9 Medium - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Cleartext storage of sensitive information in the database

Sensitive data in the user account database table including security keys and personal credentials was stored unencrypted in the database.

Affected Products

CVE(s)

CVE-2026-3221

Remediation and Workarounds

Upgrade to DVLS 2025.3.15