SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-90971

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via…

UnscoredEPSS —

Does this matter?

Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.

Description

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.

CVSS
Not yet scored
EPSS
No score yet
CISA KEV
Not listed
Weakness
CWE-863
Source
security@devolutions.net

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.