Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.9

Devolutions Server stores user account info in plain text, exposing it to database access

CVE-2026-3221
Summary

Devolutions Server versions 2025.3.14 and earlier store sensitive user information like passwords and authentication tokens in plaintext in its database. If an attacker gains access to the database, they can easily read this sensitive information. Update to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
devolutions devolutions_server <= 2025.3.15.0 –
Original title
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user inf...
Original description
Sensitive
user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with
access to the database to obtain sensitive user
information via direct database access.
nvd CVSS3.1 4.9
Vulnerability type
CWE-312 Cleartext Storage of Sensitive Information
Published: 25 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026