CVE-2026-17569: Medium severity Devolutions Devolutions Server vulnerability
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint.
This issue affects :
Devolutions Server 2026.2.4.0 through 2026.2.12.0 Devolutions Server 2026.1.23.0 and earlier
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17569?
The severity of CVE-2026-17569 is medium with a CVSS score of 4.3.
How do I fix CVE-2026-17569?
To fix CVE-2026-17569, upgrade Devolutions Server to version 2026.2.12.0 or later.
What is the impact of CVE-2026-17569?
CVE-2026-17569 allows an authenticated user with view-only permissions to access a stored API token.
Which versions of Devolutions Server are affected by CVE-2026-17569?
Devolutions Server versions 2026.2.4.0 through 2026.2.12.0 are affected by CVE-2026-17569.
Who needs to be concerned about CVE-2026-17569?
Organizations using Devolutions Server versions 2026.2.4.0 to 2026.2.12.0 should be concerned about CVE-2026-17569.