CVE-2026-100288: CWE-312 Cleartext Storage of Sensitive Information in Devolutions Server
Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.
AI Analysis
Technical Summary
CVE-2026-100288 is a vulnerability in Devolutions Server (version 2026.3.5.0 and earlier) where sensitive information such as external identity provider tokens and active session identifiers are stored in cleartext in the database. An attacker who gains read access to the database can retrieve these sensitive tokens and session identifiers by directly inspecting the stored records. This issue is categorized under CWE-312 (Cleartext Storage of Sensitive Information).
Potential Impact
An attacker with read access to the Devolutions Server database can obtain sensitive authentication tokens and session identifiers, potentially enabling unauthorized access or session hijacking. The impact depends on the attacker's ability to access the database but does not indicate remote exploitation without such access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict database read access to trusted personnel only and monitor for unauthorized access attempts.
CVE-2026-100288: CWE-312 Cleartext Storage of Sensitive Information in Devolutions Server
Description
Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.
Affected software
Devolutions
Server
pkg:github/devolutions/serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100288 is a vulnerability in Devolutions Server (version 2026.3.5.0 and earlier) where sensitive information such as external identity provider tokens and active session identifiers are stored in cleartext in the database. An attacker who gains read access to the database can retrieve these sensitive tokens and session identifiers by directly inspecting the stored records. This issue is categorized under CWE-312 (Cleartext Storage of Sensitive Information).
Potential Impact
An attacker with read access to the Devolutions Server database can obtain sensitive authentication tokens and session identifiers, potentially enabling unauthorized access or session hijacking. The impact depends on the attacker's ability to access the database but does not indicate remote exploitation without such access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict database read access to trusted personnel only and monitor for unauthorized access attempts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- DEVOLUTIONS
- Date Reserved
- 2026-09-25T17:24:03.494Z
- State
- PUBLISHED
Threat ID: 6abbf0c0c9b3d5d17704c503
Added to database: 09/29/2026, 17:09:20 UTC
Last enriched: 09/29/2026, 17:14:32 UTC
Last updated: 09/29/2026, 18:00:32 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.