Improper access control in the social login connection endpoint in
Devolutions Server 2026.2.5 allows an authenticated vault member to
enumerate social login entry metadata to which they are not authorized
via a crafted API request.
References
| Link | Resource |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0017/ | Vendor Advisory |
Configurations
History
18 Jun 2026, 18:30
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Devolutions
Devolutions devolutions Server |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| References | () https://devolutions.net/security/advisories/DEVO-2026-0017/ - Vendor Advisory | |
| CPE | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* |
16 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-16 20:16
Updated : 2026-06-18 18:30
NVD link : CVE-2026-12117
Mitre link : CVE-2026-12117
CVE.ORG link : CVE-2026-12117
JSON object : View
Products Affected
devolutions
- devolutions_server
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
