PatchSiren cyber security CVE debrief
CVE-2026-90969 Devolutions CVE debrief
CVE-2026-90969 Improper access control in Devolutions Server allows authenticated users lacking view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters. The vulnerability exists in Devolutions Server 2026.2.16 and earlier, posing a medium-severity risk. Administrators and users with access to the vault entry listing feature should assess their exposure and verify proper permissions and access controls to mitigate potential risks.
- Vendor
- Devolutions
- Product
- Server
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-20
Who should care
Devolutions Server administrators and users with access to the vault entry listing feature should assess their exposure and verify proper permissions and access controls. This includes reviewing and updating Devolutions Server to the latest version if affected, ensuring proper permissions are set for users, and monitoring for suspicious requests. Exposure and remediation details require verification from official sources due to limited information on the N
Why it matters
CVE-2026-90969 is a medium-severity vulnerability in Devolutions Server that allows authenticated users lacking view-password permission to obtain cleartext passwords. Defenders should verify access controls, ensure proper permissions, and monitor for suspicious requests. Exposure and remediation details require verification from official sources.
- Authenticated users may access cleartext passwords without proper authorization.
- Devolutions Server administrators must verify and restrict access to the vault entry listing feature.
- Exposure requires verification from official sources due to limited information on affected versions and remediation.
Technical summary
The vulnerability exists in the vault entry listing feature of Devolutions Server 2026.2.16 and earlier. An authenticated user lacking the view-password permission can obtain cleartext passwords by making a request to the entry listing endpoint with password disclosure parameters. This improper access control poses a medium-severity risk, allowing potential unauthorized access to sensitive information. Defenders should verify and restrict access to the vault entry listing feature, ensure proper permissions are set, and monitor for suspicious requests.
Defensive priority
Devolutions Server administrators should verify and restrict access to the vault entry listing feature, ensure proper permissions are set, and monitor for suspicious requests.
Recommended defensive actions
- Verify and restrict access to the vault entry listing feature in Devolutions Server.
- Ensure proper permissions are set for users and monitor for suspicious requests.
- Review and update Devolutions Server to the latest version if affected.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide details on the improper access control vulnerability in Devolutions Server 2026.2.16 and earlier. Evidence is based on official CVE Program and NVD sources, with limitations on affected versions and remediation details. Defenders should verify access controls, ensure proper permissions, and monitor for suspicious requests. The CVE record was published on 2026-09-15T19:17:47.060Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90969 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90969
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90969 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90969
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://devolutions.net/security/advisories/DEVO-2026-0030/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.