SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-90971

UNKNOWN · CVSS N/A EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A Server-Side Request Forgery (SSRF) vulnerability exists in the synchronization feature of Devolutions Server versions 2026.2.16 and earlier, allowing low-privileged authenticated users to exploit crafted connection definitions. This can lead to unauthorized access to other users' credentials and exposure of internal or cloud-metadata network endpoints. Organizations using affected VMware products should prioritize remediation to protect sensitive data and prevent potential credential theft.

CVE
CVE-2026-90971
Severity
UNKNOWN
CVSS
N/A
EPSS
0.14%
VMware VMWare

Original NVD Description

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.