Description
Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.
Weaknesses CWE-312
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-09-29T15:46:27.734Z

Reserved: 2026-09-25T17:24:03.494Z

Link: CVE-2026-100288

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T16:17:04.653

Modified: 2026-09-29T16:17:04.653

Link: CVE-2026-100288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information