Medium severity4.9NVD Advisory· Published Feb 25, 2026· Updated Jun 17, 2026
CVE-2026-3221
CVE-2026-3221
Description
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=2025.3.14
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*range: <2025.3.15.0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1- devolutions.net/security/advisories/DEVO-2026-0004/nvdVendor Advisory
News mentions
0No linked articles in our index yet.