Impact
Devolutions Server’s Recovery Kit response file generation feature incorrectly includes the Azure Key Vault client secret in the output file, even when the option to exclude sensitive data is enabled. The exposed secret is stored in cleartext, allowing an attacker who can access the file to obtain the Azure Key Vault client secret. The vulnerability is a classic example of confidential data leakage, identified as CWE‑200.
Affected Systems
The flaw affects Devolutions Server versions 2026.1.22.0 and 2026.2.11.0. Systems deploying either release should ascertain whether the Recovery Kit is enabled and, if so, verify that responses are not exposed to unauthorized users.
Risk and Exploitability
With a CVSS score of 3.3 the issue is classified as low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not included in the CISA KEV catalog. Exploitation appears to rely on an attacker accessing the generated recovery kit file; based on the description it is inferred that the attacker must read the file to obtain the secret. While the flaw does not enable arbitrary code execution or privilege escalation, it does expose the Azure Key Vault client secret.
OpenCVE Enrichment