Unrated severityNVD Advisory· Published Sep 15, 2026
CVE-2026-90971
CVE-2026-90971
Description
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=2026.2.16+ 1 more
- (no CPE)range: <=2026.2.16
- (no CPE)range: <=2026.2.16
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.