CVE Database
/

CVE-2025-12808

Back to search

CVE-2025-12808

Published: Nov 6, 2025

Modified: Nov 7, 2025

PUBLISHED

Description

Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through 2025.3.5.0 * Devolutions Server 2025.2.15.0 and earlier

VendorProductVersions

Devolutions

Server

affected
2025.3.2.0 - <= 2025.3.5.0
affected
0 - <= 2025.2.15.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now