Junglewise Threat Intelligence

CVE-2026-90971: Devolutions Server SSRF in VMware synchronization feature

CVE-2026-90971 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

Devolutions Server is a centralized platform for managing remote connections and credentials across enterprise IT infrastructure. A Server-Side Request Forgery vulnerability in its VMware datacenter discovery feature allows authenticated users with low privileges to extract other users' stored credentials and access internal or cloud-hosted network endpoints. This could lead to lateral movement within a network, credential theft, and exposure of sensitive infrastructure.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) flaw in the VMware synchronization feature of Devolutions Server versions 2026.2.16 and earlier. A low-privileged authenticated user can exploit this by submitting a specially crafted connection definition during datacenter discovery to redirect the server's outbound requests to arbitrary internal or cloud-metadata endpoints. This allows attackers to retrieve other users' credentials stored within the system and reach restricted network resources normally inaccessible to their privilege level. The attack requires valid authentication credentials but no additional user interaction. Patches for this vulnerability are expected to be available in Devolutions Server versions after 2026.2.16.

Affected products

  • Devolutions Server 2026.2.16 and earlier

Timeline

  • 2026-09-15: disclosed

References