PT-2026-35724 · Devolutions · Devolutions Server
Supr4S
·
Published
2026-04-28
·
Updated
2026-05-04
·
CVE-2026-6706
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Devolutions Server versions prior to 2026.1.14.1
Description
Improper access control in the vault documentation feature allows an authenticated attacker to read documentation content from unauthorized vaults by sending a crafted API request.
Recommendations
Update to a version later than 2026.1.14.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Devolutions Server