CVE-2026-12117
Awaiting Analysis
Awaiting Analysis - Queue
Improper Access Control in Devolutions Server 2026.2.5
Publication date: 2026-06-16
Last updated on: 2026-06-16
Assigner: Devolutions Inc.
Description
Description
Improper access control in the social login connection endpoint in
Devolutions Server 2026.2.5 allows an authenticated vault member to
enumerate social login entry metadata to which they are not authorized
via a crafted API request.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| devolutions | server | 2026.2.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |