Devolutions Server Access Control Vulnerability in DVLS REST API Endpoints

Vulnerability

A vulnerability exists in Devolutions Server in versions through 2025.3.14.0, where improper access control in multiple DVLS REST API endpoints allows authenticated users with view-only permission to access sensitive connection data. This issue arises from a permission cache poisoning vulnerability, which enables users to bypass restrictions and retrieve confidential information through the /api/connections/{id} endpoints.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive connection data for users with view-only permissions.

Remediation

Users are advised to upgrade to Devolutions Server version 2025.3.15.

Added: Feb 24, 2026, 8:30 PM
Updated: Feb 24, 2026, 9:56 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.