CVE Database
/

CVE-2026-6706

Back to search

CVE-2026-6706

Published: Apr 28, 2026

Modified: Apr 30, 2026

PUBLISHED

Description

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0.

VendorProductVersions

Devolutions

Server

affected
2026.1.6.0 - <= 2026.1.14.0
affected
0 - <= 2025.3.18.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now