MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0034

Devolutions Server is affected by multiple vulnerabilities.

Affected Products

Devolutions Server
2026.3.5.0 and earlier

Change Log

Initial publication - 2026-09-29

Cleartext storage of authentication and session tokens

6.9 Medium - CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N

Cleartext storage of sensitive information in the database in Devolutions Server allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.

CVE(s)

CVE-2026-100288

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.18.0 or 2026.3.7.0 or higher.

Missing authorization on integration settings endpoint

6.5 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Missing authorization in the data source settings API in Devolutions Server allows an authenticated non-administrative user to disclose integration secrets via a crafted API request.

CVE(s)

CVE-2026-100286

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.18.0 or 2026.3.7.0 or higher.

Credits

dorjoo

Improper access control on System Vault partial connection endpoints

5.4 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Improper access control in the partial connection API in Devolutions Server allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request.

CVE(s)

CVE-2026-93332

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.18.0 or 2026.3.7.0 or higher.

Credits

rizalyeswehack

Missing authorization on attachment history endpoints

5.4 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Missing authorization in the attachment history API in Devolutions Server allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request.

CVE(s)

CVE-2026-100287

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.18.0 or 2026.3.7.0 or higher.

Credits

rizalyeswehack

Missing authorization on gateway network scan token endpoint

5 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Missing authorization in the gateway network scan token API in Devolutions Server allows an authenticated low-privileged user to generate a network scan token and perform internal network discovery and port scanning through the gateway via a crafted API request.

CVE(s)

CVE-2026-100289

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.18.0 or 2026.3.7.0 or higher.

Credits

abfe

Incorrect behavior order bypasses the Devolutions Gateway host ruleset

2.3 Low - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N

Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.

CVE(s)

CVE-2026-93330

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.18.0 or 2026.3.7.0 or higher.