Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2026-0011
Devolutions Server is affected by an improper access control vulnerability.
Affected Products
Change Log
Initial publication - 2026-04-28
4.3 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Improper access control on documentation endpoints
Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.
This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.
Affected Products
CVE(s)
CVE-2026-6706
Remediation and Workarounds
Upgrade to Devolutions Server 2026.1.15.0 or higher.
Upgrade to Devolutions Server 2025.3.19.0 or higher.
Credits
Supr4s