Cleartext storage of sensitive information in the database in Devolutions ServerĀ 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.