Impact
The vulnerability is a Server‑Side Request Forgery. A low‑privileged authenticated user can submit a crafted connection definition for datacenter discovery, enabling the server to reach internal or cloud‑metadata network endpoints and obtain other users' credentials. This weakness is CWE‑863 and can provide an attacker unauthorized access to sensitive information.
Affected Systems
Devolutions Server versions 2026.2.16 and earlier are affected. All deployments of the VMware synchronization feature in these releases may permit the described SSRF attack.
Risk and Exploitability
The exploit requires only authenticated access, so any user with limited privileges can potentially abuse the flaw. While the EPSS score is 0.00138 (below 1%) and the vulnerability is not listed in the CISA KEV catalog, the ability to retrieve other users’ credentials and reach internal services presents a moderate to high risk if an attacker can reach the system. The attack vector is inferred to be local to the target environment via the documented datacenter discovery feature.
OpenCVE Enrichment