Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request.
This issue affects :
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Devolutions_server | Devolutions | * | 2026.1.21.0 (excluding) |
| Devolutions_server | Devolutions | 2026.2.4.0 (including) | 2026.2.4.0 (including) |