CVE-2026-100288
Summary
| CVE | CVE-2026-100288 |
|---|---|
| State | PUBLISHED |
| Assigner | DEVOLUTIONS |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-29 16:17:04 UTC |
| Updated | 2026-09-30 21:16:53 UTC |
| Description | Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records. |
Risk And Classification
Primary CVSS: v3.1 7.2 HIGH from ADP
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Problem Types: CWE-312 | CWE-312 CWE-312 Cleartext Storage of Sensitive Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.2 | HIGH | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.2 | HIGH | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Devolutions | Server | affected 2026.3.7.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| devolutions.net/security/advisories/DEVO-2026-0034 | [email protected] | devolutions.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.