Executive brief
Devolutions Server, a centralized platform for managing remote connections and passwords, contains a security flaw in its ticketing system integration. An authorized user with low-level permissions can exploit this flaw to view sensitive login credentials for connected ticketing systems in plain text. This could allow an internal user to gain unauthorized access to other corporate systems or sensitive support data.
Technical details
An improper access control vulnerability (CWE-312) exists within the ticketing integration settings of Devolutions Server. The flaw allows an authenticated user with minimal privileges to bypass intended restrictions and access sensitive configuration data. By sending a specially crafted API request to the server, an attacker can retrieve cleartext credentials for any configured ticketing system integrations. This issue is resolved in Devolutions Server versions 2026.2.5.0 and 2026.1.21.0.
Affected products
- Devolutions Devolutions Server 2026.2.4.0, 2026.1.20.0 and earlier
Timeline
- 2026-06-03: advisory: Initial internal advisory publication by Devolutions
- 2026-06-08: disclosed: CVE published to NVD dataset