Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN900 _____________________________________________________________________ DATE : 16/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Devolutions Server versions prior to 2026.3.5.0, 2026.2.17. ===================================================================== https://devolutions.net/security/advisories/DEVO-2026-0030/ _____________________________________________________________________ DEVO-2026-0030 Devolutions Server is affected by multiple vulnerabilities. Affected Products Devolutions Server 2026.2.16 and earlier Change Log Initial publication - 2026-09-15 Improper certificate validation on LDAPS connections to Active Directory 8.3 High - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Improper certificate validation on LDAPS connections to Active Directory allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate. CVE(s) CVE-2026-13327 Remediation and Workarounds Upgrade to Devolutions Server 2026.3.5.0 or higher. Credits wlayzz Improper access control on vault entry listing discloses passwords 6.5 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Improper access control in the vault entry listing feature allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters. CVE(s) CVE-2026-90969 Remediation and Workarounds Upgrade to Devolutions Server 2026.3.5.0 or higher, 2026.2.17 or higher. Credits dorjoo Server-side request forgery and credential leak via VMware connection sync endpoint 6.5 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Server-Side Request Forgery (SSRF) in the VMware synchronization feature allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery. CVE(s) CVE-2026-90971 Remediation and Workarounds Upgrade to Devolutions Server 2026.3.5.0 or higher. Credits dorjoo Improper certificate validation in Devolutions Server HTTP clients 6.3 Medium - CVSS:4.0/AV:N/AC:L/AT/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Improper certificate validation in the shared HTTP client used by synchronization and integration features allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate. CVE(s) CVE-2026-84850 Remediation and Workarounds Upgrade to Devolutions Server 2026.3.5.0 or higher. ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================