PT-2026-21792 · Devolutions · Devolutions Server

Dcit A.S

+1

·

Published

2026-02-24

·

Updated

2026-02-25

·

CVE-2026-3131

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.3.14.0 and earlier
Description An issue exists in Devolutions Server where improper access control in several DVLS REST API endpoints allows an authenticated user with view-only permissions to access sensitive connection data. The affected endpoints are not explicitly specified. The vulnerable parameters or variables are not specified.
Recommendations Update Devolutions Server to a version later than 2025.3.14.0.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-3131

Affected Products

Devolutions Server