CVE-2025-12808: Devolutions Server
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through 2025.3.5.0 * Devolutions Server 2025.2.15.0 and earlier
Affected products
- Devolutions Devolutions Server: before 2025.2.17.0 (fixed in 2025.2.17.0); from 2025.3.2.0, before 2025.3.6.0 (fixed in 2025.3.6.0)
Published 2025-11-06. Last modified 2026-10-07.