Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90971

Опубликовано: 15 сент. 2026
Источник: nvd
EPSS Низкий

Описание

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.

EPSS

Процентиль: 4%
0.00138
Низкий

Дефекты

CWE-863

Связанные уязвимости

github
4 дня назад

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter discovery.

EPSS

Процентиль: 4%
0.00138
Низкий

Дефекты

CWE-863