What is CVE-2026-17569?
CVE-2026-17569 is an improper access control vulnerability in the NetBox synchronizer of Devolutions Server. It allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. Affected versions include Devolutions Server 2026.2.4.0 through 2026.2.12.0, requiring immediate patching and token rotation.
Azərbaycanca: CVE-2026-17569 Devolutions Server-in NetBox sinxronizasiya komponentində düzgün olmayan giriş nəzarəti zəifliyidir. Bu zəiflik yalnız baxış (view-only) icazəsi olan autentifikasiya olunmuş istifadəçiyə qismən qoşulma (partial connection) endpoint-i vasitəsilə API tokeni əldə etməyə imkan verir. Devolutions Server-in 2026.2.4.0-dən 2026.2.12.0-a qədər versiyaları təsirlənir, administratorlar dərhal proqramı yeniləməli və API tokenləri rotasiya etməlidir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Devolutions
FAQ1
What can an attacker obtain by exploiting CVE-2026-17569?
The vulnerability allows an authenticated user with view-only permission to obtain a stored API token via the partial connection endpoint in the NetBox synchronizer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.