Security Advisory

CVE-2026-90971

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 19:07:02
Last updated 2026-09-15 19:07:02
Assigner DEVOLUTIONS
CVSS score not scored
State PUBLISHED

Description

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.