HomeDefault status
unaffected
2026.1.6.0 (custom)
affected
Any version
affected
Description
Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.
Problem types
CWE-862: Missing Authorization
Product status
2026.1.6.0 (custom)
Any version
References
devolutions.net/security/advisories/DEVO-2026-0011