HomeDefault status
unaffected
Any version before 2025.3.15
affected
Description
Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version before 2025.3.15
References
devolutions.net/security/advisories/DEVO-2026-0004/