VulnerabilityReceived
CVE-2026-90969
Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with…
UnscoredEPSS —
Does this matter?
Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.
Description
Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.
- CVSS
- Not yet scored
- EPSS
- No score yet
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Source
- security@devolutions.net
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.