Devolutions Server Sealed Entry Notification Bypass Vulnerability

Vulnerability

A vulnerability in Devolutions Server's entry sensitive-data retrieval feature allows an authenticated user with access to a sealed entry to retrieve its sensitive data without triggering the unseal audit notification. This is achieved through a crafted API request. The issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0, as well as versions 2025.3.20.0 and earlier.

Impact

Exploitation of this vulnerability allows for unauthorized retrieval of sensitive data from sealed entries, bypassing established audit notification protocols.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or version 2025.3.22.0 or higher.

Added: May 26, 2026, 3:41 PM
Updated: May 26, 2026, 3:41 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
3.1
exploitability
4.8
remediation
7.7
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.