CVE-2026-12117
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Improper access control in the social login connection endpoint in
Devolutions Server 2026.2.5 allows an authenticated vault member to
enumerate social login entry metadata to which they are not authorized
via a crafted API request.
Affected (1)
Products: Devolutions: Devolutions Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2026.2.4.0 to 2026.2.7.0 |
References (1)
Source: security@devolutions.net
Vendor Advisory
Timeline
No history available yet.