Junglewise Threat Intelligence

CVE-2026-90969: Devolutions Server improper access control in vault entry listing

CVE-2026-90969 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

Devolutions Server is an enterprise password and connection management platform used to securely store and manage credentials across organizations. An authenticated user without proper viewing permissions can bypass access controls to retrieve cleartext passwords through a vulnerability in the vault entry listing endpoint, potentially exposing sensitive credentials that should have been restricted.

Technical details

This is an improper access control vulnerability in Devolutions Server's vault entry listing feature. An authenticated user lacking the view-password permission can exploit the entry listing endpoint by including password disclosure parameters to retrieve cleartext passwords they should not have access to. The vulnerability affects versions 2026.2.16 and earlier, and requires an attacker to be authenticated to the system. The attack succeeds due to insufficient authorization checks on password data returned in the listing endpoint response. A patch is expected to be available via Devolutions' security advisory DEVO-2026-0030.

Affected products

  • Devolutions Server 2026.2.16 and earlier

Timeline

  • 2026-09-15: disclosed

References