Impact
Improper access control in Devolutions Server’s vault entry listing feature allows an authenticated user without view‑password permission to retrieve cleartext passwords through the entry listing endpoint. The server returns passwords in plain text when the request includes password disclosure parameters, violating the principle of least privilege. This flaw enables attackers to obtain credentials that should remain hidden and can compromise other systems that rely on those passwords.
Affected Systems
Devolutions Server versions 2026.2.16 and earlier are vulnerable. The product affected is the Devolutions edition before the patched release is at risk.
Risk and Exploitability
Exploitability requires only a valid authenticated account; no elevated privileges are needed. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation yet, but the impact of leaked credentials is high. The risk remains significant until a patched version or mitigation is applied.
OpenCVE Enrichment