MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0011

Devolutions Server is affected by an improper access control vulnerability.

Affected Products

Devolutions Server
2026.1.14.0 and earlier

Change Log

Initial publication - 2026-04-28

4.3 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Improper access control on documentation endpoints

Improper access control in the vault documentation feature in Devolutions Server 2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.

Affected Products

CVE(s)

CVE-2026-6706

Remediation and Workarounds

Upgrade to Devolutions Server 2026.1.15.0 or higher.

Credits

Supr4s