PT-2026-47430 · Devolutions · Server

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-10786

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request.
This issue affects :
  • Devolutions Server 2026.2.4.0
  • Devolutions Server 2026.1.20.0 and earlier

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2026-10786

Affected Products

Server