CVE-2026-100288

high

Description

Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.

References

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89025

https://devolutions.net/security/advisories/DEVO-2026-0034/

Details

Source: Mitre, NVD

Published: 2026-09-29

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 5.3

Vector: CVSS2#AV:L/AC:H/Au:M/C:C/I:C/A:N

Severity: Medium

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Severity: High

EPSS

EPSS: 0.00068