HomeDefault status
unaffected
Any version before 2025.3.15
affected
Description
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
Problem types
CWE-312 Cleartext Storage of Sensitive Information
Product status
Any version before 2025.3.15
References
devolutions.net/security/advisories/DEVO-2026-0004/