SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-90969

UNKNOWN · CVSS N/A EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Devolutions Server versions 2026.2.16 and earlier have an improper access control vulnerability in the vault entry listing feature, enabling authenticated users without the view-password permission to access cleartext passwords through specific requests. This could lead to unauthorized exposure of sensitive credentials, posing a significant risk to organizations using affected versions. Administrators of Devolutions Server should prioritize applying updates to mitigate this security issue.

CVE
CVE-2026-90969
Severity
UNKNOWN
CVSS
N/A
EPSS
0.14%

Original NVD Description

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.