Description
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential compromise via SSRF
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a Server‑Side Request Forgery. A low‑privileged authenticated user can submit a crafted connection definition for datacenter discovery, enabling the server to reach internal or cloud‑metadata network endpoints and obtain other users' credentials. This weakness is CWE-863 and can provide an attacker unauthorized access to sensitive information.

Affected Systems

Devolutions Server versions 2026.2.16 and earlier are affected. All deployments of the VMware synchronization feature in these releases may permit the described SSRF attack.

Risk and Exploitability

The exploit requires only authenticated access, so any user with limited privileges can potentially abuse the flaw. While the EPSS score is below 1% and the CVSS score is 6.5, the vulnerability is not listed in the CISA KEV catalog, the ability to retrieve other users’ credentials and reach internal services presents a moderate risk if an attacker can reach the system. The attack vector is inferred to be local to the target environment via the documented datacenter discovery feature.

Generated by OpenCVE AI on September 20, 2026 at 12:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Devolutions Server to a version newer than 2026.2.16 that contains the SSRF fix.
  • If a patch is not immediately available, disable or restrict the VMware synchronization feature to prevent crafted connection definitions from being accepted.
  • Implement network segmentation so that the server cannot reach internal or cloud‑metadata endpoints, limiting the impact of any remaining SSRF attempts.
  • Monitor authentication and datacenter discovery logs for unusual patterns that may indicate exploitation.

Generated by OpenCVE AI on September 20, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Devolutions Server SSRF Enables Credential Compromise

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title SSRF in VMware Sync Lets Authenticated Users Steal Credentials

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title SSRF in VMware Sync Lets Authenticated Users Steal Credentials

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
Weaknesses CWE-863
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-09-20T00:36:28.495Z

Reserved: 2026-09-14T13:37:07.584Z

Link: CVE-2026-90971

cve-icon Vulnrichment

Updated: 2026-09-20T00:36:23.251Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:47.170

Modified: 2026-09-20T01:16:33.143

Link: CVE-2026-90971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:00:11Z

Weaknesses