CVE-2026-3131
EUVD-2026-855624.02.2026, 20:27
Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| devolutions | devolutions_server | 𝑥 < 2025.3.15.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration