Junglewise Threat Intelligence

CVE-2026-15642: Devolutions Server sensitive information disclosure in Recovery Kit response file

CVE-2026-15642 · Severity: info · CVSS 0 · Published 2026-07-14

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a platform for managing remote connections and privileged access, contains a flaw in its Recovery Kit generation tool. When creating a recovery response file, the system may include sensitive Azure Key Vault credentials in plain text, even if the user specifically chooses to exclude sensitive data. If an unauthorized person gains access to this generated file, they could obtain administrative secrets used to access cloud resources, potentially leading to a broader breach of the organization's Azure environment.

Technical details

An information disclosure vulnerability (CWE-200) exists in Devolutions Server's Recovery Kit response file generation feature. The root cause is the improper handling of sensitive data during file generation, which results in the Azure Key Vault client secret being written to the response file in cleartext. This occurs even if the administrator explicitly selects the option to exclude sensitive information. An attacker who obtains access to this generated file (via local access or insecure storage) can retrieve the secret. The issue affects versions 2026.1.22.0 and 2026.2.11.0 and earlier, and is fixed in versions 2026.1.23.0 and 2026.2.12.0.

Affected products

  • Devolutions Server 2026.1.22.0 and earlier, 2026.2.11.0 and earlier

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: disclosed
  • 2026-07-14: patched

References