CyberRota Analysis
AI-GeneratedDevolutions Server versions 2026.2.16 and earlier have an improper access control vulnerability in the vault entry listing feature, enabling authenticated users without the view-password permission to access cleartext passwords through specific requests. This could lead to unauthorized exposure of sensitive credentials, posing a significant risk to organizations using affected versions. Administrators of Devolutions Server should prioritize applying updates to mitigate this security issue.
Original NVD Description
Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.