Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2025.3.14.0
A vulnerability exists in Devolutions Server in versions through 2025.3.14.0, where improper access control in multiple DVLS REST API endpoints allows authenticated users with view-only permission to access sensitive connection data. This issue arises from a permission cache poisoning vulnerability, which enables users to bypass restrictions and retrieve confidential information through the /api/connections/{id} endpoints.
Exploitation of this vulnerability leads to unauthorized access to sensitive connection data for users with view-only permissions.
Users are advised to upgrade to Devolutions Server version 2025.3.15.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.