CVE-2026-3131: Infoleak
Published Feb 24, 2026
·Updated
Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.
Affected Software
2 affected components
Devolutions Server<2025.3.14.0
Devolutions Devolutions Server<2025.3.15.0
Event History
Feb 24, 2026
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
DescriptionWeakness
Data Sourced
via NVD·08:27 PM
DescriptionSeverityWeaknessAffected Software
Jan 4, 58137
Event
via FIRST·12:44 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-3131?
The severity of CVE-2026-3131 is critical due to improper access control affecting sensitive data.
2
How do I fix CVE-2026-3131?
To fix CVE-2026-3131, upgrade Devolutions Server to version 2025.3.15.0 or later.
3
What type of vulnerability is CVE-2026-3131?
CVE-2026-3131 is classified as an improper access control vulnerability.
4
Who is affected by CVE-2026-3131?
Authenticated users with view-only permission in versions of Devolutions Server up to 2025.3.14.0 are affected by CVE-2026-3131.
5
What data is at risk with CVE-2026-3131?
CVE-2026-3131 allows access to sensitive connection data that should be restricted.