CVE-2026-100288 PUBLISHED

Assigner: DEVOLUTIONS
Reserved: 25.09.2026 Published: 29.09.2026 Updated: 29.09.2026

Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.

Product Status

Vendor Devolutions
Product Server
Versions Default: unaffected
  • affected from 0 to 2026.3.7.0 (excl.)

References

Problem Types

  • CWE-312 Cleartext Storage of Sensitive Information CWE