CVE-2026-3204 PUBLISHED

Assigner: DEVOLUTIONS
Reserved: 25.02.2026 Published: 03.03.2026 Updated: 04.03.2026

Improper input validation in the error message page in Devolutions Server 2025.3.15 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.

Product Status

Vendor Devolutions
Product Server
Versions Default: unaffected
  • affected from 0 to 2025.3.16 (excl.)

References

Problem Types

  • CWE-20 Improper Input Validation CWE