ZeroHour

CVE-2026-3221

CVSS 3.1
4.9 medium
EPSS
<1%p5
Published
()
Modified
Description

Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.

Vendors
devolutions
Products
devolutions server
Weakness
CWE-312
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.