CVE-2026-4989: Devolutions Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from 2026.1.1 through 2026.1.11, from 2025.3.1 through 2025.3.17.
Affected products
- Devolutions Devolutions Server: from 2025.3.1.0, before 2025.3.18.0 (fixed in 2025.3.18.0); from 2026.1.1.0, before 2026.1.12.0 (fixed in 2026.1.12.0)
Published 2026-04-01. Last modified 2026-06-17.