← back
CVE-2026-3221

CVE-2026-3221

CVSS 4.9 MEDIUMEPSS 0.2%CWE-312
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
Devolutions · Server

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →