CVE-2026-3221: Medium severity Devolutions Server vulnerability
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3221?
CVE-2026-3221 is considered a critical vulnerability due to the exposure of sensitive user account information.
How do I fix CVE-2026-3221?
To fix CVE-2026-3221, upgrade to Devolutions Server version 2025.3.15 or later, where sensitive data is properly encrypted.
What type of information is exposed by CVE-2026-3221?
CVE-2026-3221 exposes sensitive user account information stored in the database without encryption.
Who is affected by CVE-2026-3221?
CVE-2026-3221 affects users of Devolutions Server versions up to and including 2025.3.14.
What are the potential consequences of CVE-2026-3221?
The potential consequences of CVE-2026-3221 include unauthorized access to sensitive user account details, leading to data breaches.