Devolutions Server Cleartext Storage of Sensitive User Information Vulnerability

Vulnerability

A vulnerability exists in Devolutions Server in versions through 2025.3.14 that allows for the exposure of sensitive user account information. This issue arises because the database stores critical data, including security keys and personal credentials, in an unencrypted format. As a result, an attacker with direct access to the database can retrieve this sensitive information.

Impact

Exploitation of this vulnerability leads to the unauthorized access of sensitive user information, including security keys and personal credentials, stored in the database.

Remediation

Users are advised to upgrade to Devolutions Server version 2025.3.15.

Added: Feb 25, 2026, 10:42 PM
Updated: Feb 25, 2026, 10:42 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
3.9
remediation
7.7
relevance
3.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.