Description
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
Published: 2026-09-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Credential compromise via SSRF
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a Server‑Side Request Forgery. A low‑privileged authenticated user can submit a crafted connection definition for datacenter discovery, enabling the server to reach internal or cloud‑metadata network endpoints and obtain other users' credentials. This weakness is CWE‑863 and can provide an attacker unauthorized access to sensitive information.

Affected Systems

Devolutions Server versions 2026.2.16 and earlier are affected. All deployments of the VMware synchronization feature in these releases may permit the described SSRF attack.

Risk and Exploitability

The exploit requires only authenticated access, so any user with limited privileges can potentially abuse the flaw. While the EPSS score is 0.00138 (below 1%) and the vulnerability is not listed in the CISA KEV catalog, the ability to retrieve other users’ credentials and reach internal services presents a moderate to high risk if an attacker can reach the system. The attack vector is inferred to be local to the target environment via the documented datacenter discovery feature.

Generated by OpenCVE AI on September 17, 2026 at 08:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Devolutions Server to a version newer than 2026.2.16 that contains the SSRF fix.
  • If a patch is not immediately available, disable or restrict the VMware synchronization feature to prevent crafted connection definitions from being accepted.
  • Implement network segmentation so that the server cannot reach internal or cloud‑metadata endpoints, limiting the impact of any remaining SSRF attempts.
  • Monitor authentication and datacenter discovery logs for unusual patterns that may indicate exploitation.

Generated by OpenCVE AI on September 17, 2026 at 08:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title SSRF in VMware Sync Lets Authenticated Users Steal Credentials

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title SSRF in VMware Sync Lets Authenticated Users Steal Credentials

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
Weaknesses CWE-863
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-09-15T19:07:02.950Z

Reserved: 2026-09-14T13:37:07.584Z

Link: CVE-2026-90971

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:47.170

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-90971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:15:07Z

Weaknesses