Sceawere

Vulnerability Detail

CVE-2026-100286UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthorized Integration Secret Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
9h ago
Vendor
Devolutions
Product
Server
Attack Type
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-29T16:17:04.420Z",
  "pubdate": "2026-09-29T16:17:04.420Z",
  "executiveSummary": "A vulnerability exists in the data source settings API of Devolutions Server version 2026.3.5.0 and earlier that results in an improper authorization flaw.\nThis vulnerability allows an authenticated, non-administrative user to bypass intended access controls and retrieve sensitive integration secrets.\nThe issue stems from a failure to validate user permissions during API requests directed at the data source configuration endpoint.\nSuccessful exploitation exposes critical credentials used for third-party integrations, potentially leading to unauthorized access to linked external systems, privilege escalation, or systemic compromise of the Devolutions Server environment.\nThe vulnerability is limited to authenticated users, meaning an attacker must possess a valid, non-privileged user account to perform the exploit.\nThe risk is categorized as high, as the exposure of integration secrets typically provides a pathway for lateral movement and further exploitation of the enterprise infrastructure.",
  "technicalDetails": "The root cause of this vulnerability is an Insecure Direct Object Reference (IDOR) or a broken object-level authorization (BOLA) pattern within the data source settings API component of Devolutions Server.\nSpecifically, the server-side logic responsible for handling API calls to the data source configuration endpoint fails to enforce strict authorization checks based on the requesting user's security role.\nWhile the API is intended to be restricted to administrative accounts, the system does not properly verify that the authenticated user possesses the 'Administrator' privilege before serving the configuration payload.\nThe attack flow begins with an authenticated user crafting a specific, well-formed API request targeting the data source settings endpoint. Because the application logic fails to validate the user's authorization level against the specific resource, the API processes the request as if it originated from a privileged context.\nUpon receiving the request, the backend retrieves the requested configuration data, which includes sensitive integration secrets (e.g., API keys, service account credentials, or OAuth tokens used for external integrations).\nThe application then returns this sensitive data in the HTTP response body, effectively disclosing the secrets to the unprivileged attacker.\nThis exploitation method requires the attacker to be authenticated within the Devolutions Server instance, ensuring the session is active. However, the attacker does not require administrative privileges, circumventing the intended security model.\nThe vulnerable component is the data source settings API module, which processes configuration requests. All versions of Devolutions Server up to and including 2026.3.5.0 are confirmed to be susceptible to this flaw.\nPost-exploitation, the impact is significant: once an attacker successfully extracts integration secrets, they can use these credentials to authenticate to external systems that the Devolutions Server interacts with. This effectively grants the attacker the permissions associated with those integration accounts, leading to a loss of confidentiality and integrity for both the Devolutions Server and the integrated infrastructure. The lack of proper server-side authorization allows for this information leakage without leaving logs that might typically indicate a privilege violation, as the system treats the request as a routine data retrieval operation."
}
CVE-2026-100286: Unauthorized Integration Secret Disclosure (MEDIUM Severity, CVSS: 6.5) | Sceawere