CVE-2026-90971
—CVSS
—
EPSS
—
Published
()
Modified
Description
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
- Weakness
- CWE-863
In the news0 stories
No ingested article mentions this CVE yet.