CVE-2026-3221: Devolutions Server
Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
Affected products
- Devolutions Devolutions Server: before 2025.3.15.0 (fixed in 2025.3.15.0)
Published 2026-02-25. Last modified 2026-06-17.