By weakness (CWE)

CWE-882: related vulnerabilities

CVEs classified under CWE-882. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

1 published vulnerability

  • CVE-2026-11890MEDIUM 4.3

    Devolutions Server versions 2026.2.5 and 2026.1.21 contain an access control flaw that allows any authenticated user to view account discovery scan results they should not have permission to access. An attacker with valid credentials to the server can retrieve sensitive account information gathered during automated discovery scans, potentially exposing credentials or account details that should be restricted to authorized administrators.