HomeDefault status
unaffected
Any version
affected
Description
Improper access control in the vault documentation feature in Devolutions Server 2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.
Problem types
CWE-862: Missing Authorization
Product status
Any version
References
devolutions.net/security/advisories/DEVO-2026-0011