Junglewise Threat Intelligence

CVE-2026-17569: Devolutions Server improper access control in NetBox synchronizer

CVE-2026-17569 · Severity: info · CVSS 6.3 · Published 2026-07-27

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and credentials, contains a security flaw in its NetBox integration. An authenticated user who only has permission to view a specific entry can exploit this flaw to extract sensitive API tokens. This could allow an unauthorized individual to gain broader access to integrated NetBox resources, potentially compromising infrastructure data.

Technical details

An improper access control vulnerability (CWE-522) exists in the NetBox synchronizer component of Devolutions Server. The flaw is located within the partial connection endpoint, which fails to properly restrict access to sensitive credential data. An attacker with valid authentication and 'view-only' permissions on a specific entry can make a crafted request to this endpoint to retrieve stored NetBox API tokens. This vulnerability affects versions 2026.2.12.0 and earlier, as well as 2026.1.23.0 and earlier. Users are advised to upgrade to version 2026.1.24.0 or 2026.2.14.0 to remediate the issue.

Affected products

  • Devolutions Server 2026.2.4.0 through 2026.2.12.0, 2026.1.23.0 and earlier

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory

References