Impact
An improperly implemented access control in the NetBox synchronizer of Devolutions Server allows an authenticated user with only view‑only permission to retrieve a stored API token through the partial connection endpoint. This flaw can expose credential material that could be later used to impersonate services or seek further access, constituting an unauthorized disclosure vulnerability (CWE‑522).
Affected Systems
The affected products are Devolutions Server. Versions 2026.2.4.0 through 2026.2.12.0 and all releases 2026.1.23.0 and earlier are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 classifies this vulnerability as low, and the EPSS score less than 1% indicates a very small likelihood of exploitation in the general population. Nevertheless, because any authenticated user with view‑only rights can acquire a stored API token, an attacker can obtain credentials that may lead to further privilege escalation or service impersonation. No public exploit has been documented, and the flaw is not listed in the CISA KEV catalog, but the credential exposure itself remains a confidentiality risk for affected environments.
OpenCVE Enrichment