Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request.
This issue affects :
* Devolutions Server 2026.1.6.0 through 2026.1.16.0
* Devolutions Server 2025.3.20.0 and earlier
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0013/ |
|
History
Fri, 22 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Access Control Allows Retrieval of Sealed Entry Documents via API |
Fri, 22 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 22 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Access Control Allows Retrieval of Sealed Entry Documents via API | |
| First Time appeared |
Devolutions
Devolutions server |
|
| Vendors & Products |
Devolutions
Devolutions server |
Fri, 22 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier | |
| Weaknesses | CWE-862 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-05-22T16:52:43.390Z
Reserved: 2026-05-21T19:43:31.959Z
Link: CVE-2026-9246
Updated: 2026-05-22T16:52:27.325Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-22T18:30:42Z