Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2026.1.16.0
- <= 2025.3.20.0
A vulnerability exists in Devolutions Server in versions through 2026.1.16.0, allowing low-privileged authenticated users to create new vaults by sending a crafted import request. This issue arises from missing authorization in the vault import feature.
Exploitation of this vulnerability allows for unauthorized creation of vaults, potentially leading to unauthorized access or management of sensitive information within those vaults.
Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.