Description
Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.
Published: 2026-09-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Credential disclosure via cleartext passwords
Action: Upgrade Now
AI Analysis

Impact

Improper access control in Devolutions Server’s vault entry listing feature allows an authenticated user without view‑password permission to retrieve cleartext passwords through the entry listing endpoint. The server returns passwords in plain text when the request includes password disclosure parameters, violating the principle of least privilege. This flaw enables attackers to obtain credentials that should remain hidden and can compromise other systems that rely on those passwords.

Affected Systems

Devolutions Server versions 2026.2.16 and earlier are vulnerable. The product affected is the Devolutions edition before the patched release is at risk.

Risk and Exploitability

Exploitability requires only a valid authenticated account; no elevated privileges are needed. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation yet, but the impact of leaked credentials is high. The risk remains significant until a patched version or mitigation is applied.

Generated by OpenCVE AI on September 17, 2026 at 08:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a Devolutions Server version newer than 2026.2.16.
  • Remove the view-password permission from any roles that do not need it.
  • Disable the password disclosure parameters in the vault entry listing endpoint through server configuration or network controls.

Generated by OpenCVE AI on September 17, 2026 at 08:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Cleartext Password Disclosure via Improper Access Control in Devolutions Server

Wed, 16 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Cleartext Password Disclosure via Improper Access Control in Devolutions Server

Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.
Weaknesses CWE-284
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-09-15T19:09:33.847Z

Reserved: 2026-09-14T13:35:37.088Z

Link: CVE-2026-90969

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:47.060

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-90969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:15:07Z

Weaknesses