SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-90969

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with…

UnscoredEPSS —

Does this matter?

Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.

Description

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.

CVSS
Not yet scored
EPSS
No score yet
CISA KEV
Not listed
Weakness
CWE-284
Source
security@devolutions.net

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.