CVE-2026-90969

NONE EPSS 0.14%
Updated Sep 15, 2026
Vault
Parameter Value
Type CWE-284 (Improper Access Control)
Vendor Vault
Public PoC No

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.