HomeDefault status
unaffected
Any version
affected
Description
Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.
Problem types
CWE-284 Improper access control
Product status
Any version
References
devolutions.net/security/advisories/DEVO-2026-0013/