Executive brief
Devolutions Server, a centralized platform for managing remote connections and credentials, contains a flaw in its data export feature. An authorized user with export permissions can bypass security notifications when exporting sensitive 'sealed' entries. This allows a user to access protected data without alerting administrators, potentially leading to undetected data exfiltration.
Technical details
A vulnerability classified as Insufficient Logging (CWE-778) exists in the entry export component of Devolutions Server. The flaw allows an attacker who already possesses high-level export permissions to bypass the 'unseal' notification mechanism. By using a specially crafted export request, the attacker can extract sealed entries without the system generating the expected administrative alerts. This issue affects versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. Users are advised to upgrade to version 2026.1.19.0 or 2025.3.22.0 to remediate the issue.
Affected products
- Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier
Timeline
- 2026-05-21: disclosed: Initial vendor publication date
- 2026-05-22: advisory: NVD publication date