Sensitive
user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with
access to the database to obtain sensitive user
information via direct database access.
References
| Link | Resource |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0004/ | Vendor Advisory |
Configurations
History
28 Feb 2026, 00:43
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Devolutions
Devolutions devolutions Server |
|
| References | () https://devolutions.net/security/advisories/DEVO-2026-0004/ - Vendor Advisory | |
| CPE | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* |
26 Feb 2026, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
25 Feb 2026, 19:43
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-25 19:43
Updated : 2026-02-28 00:43
NVD link : CVE-2026-3221
Mitre link : CVE-2026-3221
CVE.ORG link : CVE-2026-3221
JSON object : View
Products Affected
devolutions
- devolutions_server
CWE
CWE-312
Cleartext Storage of Sensitive Information
