🔐 CVE Alert

CVE-2026-9223

MEDIUM 4.3
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

CWE CWE-284
Vendor devolutions
Product server
Published May 22, 2026
Last Updated May 22, 2026
Stay Ahead of the Next One

Get instant alerts for devolutions server

Be the first to know when new medium vulnerabilities affecting devolutions server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Devolutions / Server
0 ≤ 2026.1.16.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
devolutions.net: https://devolutions.net/security/advisories/DEVO-2026-0013/