HomeDefault status
unaffected
Any version
affected
Description
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.
Problem types
CWE-20 Improper Input Validation
Product status
Any version
References
devolutions.net/security/advisories/DEVO-2026-0005