Home

Description

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier

PUBLISHED Reserved 2026-06-03 | Published 2026-06-08 | Updated 2026-06-08 | Assigner DEVOLUTIONS

Problem types

CWE-312 Cleartext storage of sensitive information

Product status

Default status
unaffected

2026.2.4.0 (custom)
affected

Any version
affected

References

devolutions.net/security/advisories/DEVO-2026-0015/

cve.org (CVE-2026-10786)

nvd.nist.gov (CVE-2026-10786)

Download JSON