SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-17570

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Improper access control in the PAM password history endpoints of Devolutions Server allows authenticated low-privileged users to exploit crafted API requests, leading to the disclosure of plaintext credential secrets. Organizations using Devolutions Server versions 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 or earlier should prioritize remediation to mitigate potential credential exposure risks.

CVE
CVE-2026-17570
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%

Original NVD Description

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)