CVE-2026-6706

Published Apr 28, 2026

Last updated 22 days ago

Overview

Description
Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.
Source
security@devolutions.net
NVD status
Analyzed
Products
devolutions_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

security@devolutions.net
CWE-862

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.