Back to search
CVE-2026-3221
Published: Feb 25, 2026
Modified: Feb 26, 2026
PUBLISHED
Description
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
| Vendor | Product | Versions |
|---|---|---|
Devolutions | Server | affected 0 - < 2025.3.15 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now