CVE-2026-90971
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via…
Does this matter?
Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.
Description
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
- CVSS
- Not yet scored
- EPSS
- No score yet
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Source
- security@devolutions.net
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.