CVE-2026-3131: Devolutions Server

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.

Affected products

  • Devolutions Devolutions Server: before 2025.3.15.0 (fixed in 2025.3.15.0)

Published 2026-02-24. Last modified 2026-06-17.