Devolutions Server 2026.2.16 及更早版本中,vault 条目列表功能存在不当访问控制漏洞。该漏洞允许未获得“查看密码”权限的已认证用户,通过向条目列表端点发送包含密码披露参数的请求,从而获取明文密码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Devolutions | Server | ≤ 2026.2.16 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Devolutions | Server | 0 ~ 2026.2.16 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84850 | Devolutions Server 2026.2.16证书验证漏洞 | |
| CVE-2026-13327 | Devolutions Server 2.16及以前LDAPS证书验证漏洞 | |
| CVE-2026-90971 | Devolutions Server 2026.2.16 SSRF漏洞 | |
| CVE-2026-92237 | Devolutions PowerShell Universal 慢查询日志敏感信息泄露 |
No comments yet