Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 19:17
Updated : 2026-09-15 19:17
NVD link : CVE-2026-90971
Mitre link : CVE-2026-90971
CVE.ORG link : CVE-2026-90971
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
