CVE-2026-0610: SQL Injection
Published Jan 19, 2026
·Updated
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
Affected Software
2 affected components
Devolutions Server>=2025.3.1<=2025.3.12
Devolutions Devolutions Server>=2025.3.1.0<2025.3.14.0
Event History
Jan 19, 2026
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-0610?
The CVE-2026-0610 vulnerability has been classified as a critical SQL Injection issue.
2
How do I fix CVE-2026-0610?
To fix CVE-2026-0610, upgrade Devolutions Server to version 2025.3.13 or later.
3
What specific versions are affected by CVE-2026-0610?
CVE-2026-0610 affects Devolutions Server versions 2025.3.1 through 2025.3.12.
4
What kind of attack does CVE-2026-0610 enable?
CVE-2026-0610 enables attackers to perform SQL Injection attacks, potentially leading to unauthorized data access.
5
Is there a workaround for CVE-2026-0610?
Currently, the recommended action for CVE-2026-0610 is to apply the patch by upgrading to the latest version, as no official workaround is provided.