Description
Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.
Published: 2026-07-14
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Devolutions Server’s Recovery Kit response file generation feature incorrectly includes the Azure Key Vault client secret in the output file, even when the option to exclude sensitive data is enabled. The exposed secret is stored in cleartext, allowing an attacker who can access the file to obtain the Azure Key Vault client secret. The vulnerability is a classic example of confidential data leakage, identified as CWE‑200.

Affected Systems

The flaw affects Devolutions Server versions 2026.1.22.0 and 2026.2.11.0. Systems deploying either release should ascertain whether the Recovery Kit is enabled and, if so, verify that responses are not exposed to unauthorized users.

Risk and Exploitability

With a CVSS score of 3.3 the issue is classified as low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not included in the CISA KEV catalog. Exploitation appears to rely on an attacker accessing the generated recovery kit file; based on the description it is inferred that the attacker must read the file to obtain the secret. While the flaw does not enable arbitrary code execution or privilege escalation, it does expose the Azure Key Vault client secret.

Generated by OpenCVE AI on July 31, 2026 at 05:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict file‑system permissions so that only trusted administrators can read Recovery Kit output files.
  • Disable the Recovery Kit generation feature or configure it to omit Azure Key Vault secrets.
  • Remove or securely store the Azure Key Vault client secret in the server configuration before generating any recovery kits to prevent it from being written to disk.

Generated by OpenCVE AI on July 31, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Azure Key Vault Secret Disclosure via Recovery Kit Response Files in Devolutions Server

Wed, 29 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Azure Key Vault Secret Disclosure via Recovery Kit Response Files in Devolutions Server

Mon, 20 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Devolutions Server Recovery Kit Exposes Azure Key Vault Secrets

Thu, 16 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Devolutions Server Recovery Kit Exposes Azure Key Vault Secrets

Wed, 15 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.
Weaknesses CWE-200
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-15T14:43:07.544Z

Reserved: 2026-07-13T18:21:40.280Z

Link: CVE-2026-15642

cve-icon Vulnrichment

Updated: 2026-07-15T14:42:53.202Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor