{"id":"CVE-2026-93332","published":"2026-09-29T16:17:15.470","lastModified":"2026-09-29T18:56:47.113","description":"Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://devolutions.net/security/advisories/DEVO-2026-0034/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}