Home

Description

Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.

PUBLISHED Reserved 2026-02-25 | Published 2026-02-25 | Updated 2026-02-26 | Assigner DEVOLUTIONS

Problem types

CWE-312 Cleartext Storage of Sensitive Information

Product status

Default status
unaffected

Any version before 2025.3.15
affected

References

devolutions.net/security/advisories/DEVO-2026-0004/

cve.org (CVE-2026-3221)

nvd.nist.gov (CVE-2026-3221)

Download JSON