CVE-2026-9223 PUBLISHED

Assigner: DEVOLUTIONS
Reserved: 21.05.2026 Published: 22.05.2026 Updated: 22.05.2026

Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

Product Status

Vendor Devolutions
Product Server
Versions Default: unaffected
  • affected from 0 to 2026.1.16.0 (incl.)

References

Problem Types

  • CWE-284 Improper access control CWE