CVE-2026-6706

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.
Configurations

No configuration.

History

30 Apr 2026, 18:16

Type Values Removed Values Added
Summary (en) Improper access control in the vault documentation feature in Devolutions Server 2026.1.14.0 and earlier allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. (en) Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.

28 Apr 2026, 19:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

28 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 14:16

Updated : 2026-04-30 18:16


NVD link : CVE-2026-6706

Mitre link : CVE-2026-6706

CVE.ORG link : CVE-2026-6706


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization