MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0011

Devolutions Server is affected by an improper access control vulnerability.

Affected Products

Devolutions Server
2026.1.6.0 through 2026.1.14.0
Devolutions Server
2025.3.18.0 and earlier

Change Log

Initial publication - 2026-04-28

4.3 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Improper access control on documentation endpoints

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.

This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.

Affected Products

CVE(s)

CVE-2026-6706

Remediation and Workarounds

Upgrade to Devolutions Server 2026.1.15.0 or higher.

Upgrade to Devolutions Server 2025.3.19.0 or higher.

Credits

Supr4s