CVE-2026-100286: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Devolutions Server
Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request.
AI Analysis
Technical Summary
This vulnerability (CWE-200) in Devolutions Server affects versions prior to 2026.3.7.0. The issue arises from missing authorization in the data source settings API, which permits authenticated users without administrative privileges to craft API requests that disclose integration secrets. There is no CVSS score provided, and no known exploits in the wild have been reported. The vulnerability was assigned by Devolutions and publicly disclosed on September 29, 2026.
Potential Impact
An authenticated user without administrative rights can retrieve sensitive integration secrets, potentially compromising the confidentiality of critical configuration data. This could facilitate further attacks if the secrets are used to access other systems or services.
Mitigation Recommendations
Upgrade Devolutions Server to version 2026.3.7.0 or later, where this authorization issue has been fixed. Since the vulnerability is due to missing authorization checks, applying the official patch is the recommended remediation.
CVE-2026-100286: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Devolutions Server
Description
Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request.
CVSS v3.1
Score 6.5medium
Affected software
Devolutions
Server
pkg:github/devolutions/serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-200) in Devolutions Server affects versions prior to 2026.3.7.0. The issue arises from missing authorization in the data source settings API, which permits authenticated users without administrative privileges to craft API requests that disclose integration secrets. There is no CVSS score provided, and no known exploits in the wild have been reported. The vulnerability was assigned by Devolutions and publicly disclosed on September 29, 2026.
Potential Impact
An authenticated user without administrative rights can retrieve sensitive integration secrets, potentially compromising the confidentiality of critical configuration data. This could facilitate further attacks if the secrets are used to access other systems or services.
Mitigation Recommendations
Upgrade Devolutions Server to version 2026.3.7.0 or later, where this authorization issue has been fixed. Since the vulnerability is due to missing authorization checks, applying the official patch is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- DEVOLUTIONS
- Date Reserved
- 2026-09-25T17:22:20.593Z
- State
- PUBLISHED
Threat ID: 6abbddc9f7a7c5410696f02c
Added to database: 09/29/2026, 15:48:25 UTC
Last enriched: 09/29/2026, 16:02:47 UTC
Last updated: 09/29/2026, 18:00:32 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.