CVE-2026-90971: SSRF
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be an authenticated, low-privileged user of Devolutions Server and must be able to submit a crafted connection definition for VMware datacenter discovery.
What could an attacker access through this vulnerability?
The issue can be used to reach internal network endpoints or cloud-metadata endpoints. It may also allow the attacker to obtain other users' credentials.
Are environments without VMware synchronization affected?
The vulnerability is described in the VMware synchronization feature and requires a crafted connection definition submitted for datacenter discovery. The provided information does not establish exposure where that feature is not used.