4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.
Basic Information
ID
CVE-2026-9223
Source
DEVOLUTIONS
Published
May 22, 2026 at 15:21
Modified
May 22, 2026 at 16:57
Affected Product
Vendor
Devolutions
Product
Server
Affected Versions
Devolutions Server 0