Description
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint.

This issue affects :

* Devolutions Server 2026.2.4.0 through 2026.2.12.0
* Devolutions Server 2026.1.23.0 and earlier
Published: 2026-07-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improperly implemented access control in the NetBox synchronizer of Devolutions Server allows an authenticated user with only view‑only permission to retrieve a stored API token through the partial connection endpoint. This flaw can expose credential material that could be later used to impersonate services or seek further access, constituting an unauthorized disclosure vulnerability (CWE‑522).

Affected Systems

The affected products are Devolutions Server. Versions 2026.2.4.0 through 2026.2.12.0 and all releases 2026.1.23.0 and earlier are vulnerable.

Risk and Exploitability

The CVSS score of 4.3 classifies this vulnerability as low, and the EPSS score less than 1% indicates a very small likelihood of exploitation in the general population. Nevertheless, because any authenticated user with view‑only rights can acquire a stored API token, an attacker can obtain credentials that may lead to further privilege escalation or service impersonation. No public exploit has been documented, and the flaw is not listed in the CISA KEV catalog, but the credential exposure itself remains a confidentiality risk for affected environments.

Generated by OpenCVE AI on August 3, 2026 at 17:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Devolutions Server to a release newer than 2026.2.12.0 (for example, 2026.2.13.0 or later) to apply the vendor‑supplied fix.
  • Revoke view‑only permissions from users who do not require them for legitimate business purposes.
  • If an immediate upgrade is not possible, reconfigure the application to prevent view‑only users from accessing the partial connection endpoint, or isolate the endpoint from those users through network segmentation.

Generated by OpenCVE AI on August 3, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improper access control allows view‑only users to retrieve stored API tokens

Sun, 02 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Enables View‑Only Users to Retrieve Stored API Tokens in Devolutions Server

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control Enables View‑Only Users to Retrieve Stored API Tokens in Devolutions Server
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier
Weaknesses CWE-522
References

Subscriptions

Devolutions Devolutions Server Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-28T13:45:03.527Z

Reserved: 2026-07-27T15:01:45.583Z

Link: CVE-2026-17569

cve-icon Vulnrichment

Updated: 2026-07-28T13:44:55.509Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T18:16:54.393

Modified: 2026-08-03T12:31:57.233

Link: CVE-2026-17569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:15:12Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials