CVE-2026-17570: Medium severity Devolutions Devolutions Server vulnerability
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests.
This issue affects :
Devolutions Server 2026.2.4.0 through 2026.2.12.0 Devolutions Server 2026.1.23.0 and earlier
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17570?
The severity of CVE-2026-17570 is categorized as medium with a CVSS score of 4.3.
How do I fix CVE-2026-17570?
To fix CVE-2026-17570, update Devolutions Server to a version that is not affected, specifically version 2026.2.12.0 or higher.
What impact does CVE-2026-17570 have on my system?
CVE-2026-17570 allows low-privileged authenticated users to disclose plaintext credential secrets via crafted API requests.
Which versions of Devolutions Server are affected by CVE-2026-17570?
CVE-2026-17570 affects Devolutions Server versions 2026.2.4.0 through 2026.2.12.0 and version 2026.1.23.0.
What type of vulnerability is CVE-2026-17570?
CVE-2026-17570 is classified as an improper access control vulnerability.