CyberRota Analysis
AI-GeneratedA Server-Side Request Forgery (SSRF) vulnerability exists in the synchronization feature of Devolutions Server versions 2026.2.16 and earlier, allowing low-privileged authenticated users to exploit crafted connection definitions. This can lead to unauthorized access to other users' credentials and exposure of internal or cloud-metadata network endpoints. Organizations using affected VMware products should prioritize remediation to protect sensitive data and prevent potential credential theft.
Original NVD Description
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.