CVE-2026-90971
N/A
N/A
Summary
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Devolutions | Server | 0 <= 2026.2.16 | affected |
Weaknesses
- CWE-863: CWE-863 Incorrect authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.