{"id":"CVE-2026-100289","published":"2026-09-29T16:17:04.780","lastModified":"2026-09-29T18:56:47.113","description":"Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan token and perform internal network discovery and port scanning through the gateway via a crafted API request.","cvssScore":5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://devolutions.net/security/advisories/DEVO-2026-0034/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}