Description
Improper
access control in the vault documentation feature in Devolutions Server
2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.
Published: 2026-04-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 13:45:00 +0000

Type Values Removed Values Added
Description Improper access control in the vault documentation feature in Devolutions Server 2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request.
Weaknesses CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-04-28T13:11:44.350Z

Reserved: 2026-04-20T18:05:39.474Z

Link: CVE-2026-6706

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-28T14:16:14.150

Modified: 2026-04-28T14:16:14.150

Link: CVE-2026-6706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses