CVE-2026-93332: Medium severity Devolutions Devolutions Server vulnerability
Published Sep 29, 2026
·Updated
Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request.
Affected Software
1 affected component
Devolutions Devolutions Server<=2026.3.5.0
Event History
Sep 29, 2026
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated low-privileged user can exploit it. Exploitation requires sending a crafted request to the partial connection API.
2
What data or functionality is exposed?
The attacker can read, create, modify, and delete entries in the System Vault.
3
Which deployments are affected?
Devolutions Server versions 2026.3.5.0 and earlier are affected. The available information does not state whether any particular default configuration changes exposure.