What is CVE-2026-17570?
CVE-2026-17570 is an improper access control vulnerability in the PAM password history endpoints of Devolutions Server. This flaw allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. It primarily affects versions 2026.2.4.0 through 2026.2.12.0.
Azərbaycanca: CVE-2026-17570 Devolutions Server proqramında PAM parol tarixçəsi endpointlərində zəif giriş nəzarəti boşluğudur. Bu boşluq autentifikasiya olunmuş aşağı səlahiyyətli istifadəçiyə xüsusi hazırlanmış API sorğuları vasitəsilə açıq mətn şəklində etimadnamə məlumatlarını əldə etməyə imkan verir. Bu zəiflik əsasən 2026.2.4.0-dən 2026.2.12.0-a qədər olan versiyalara təsir göstərir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Devolutions
FAQ2
Does exploiting CVE-2026-17570 require the attacker to be authenticated?
Yes, exploiting CVE-2026-17570 requires the attacker to be an authenticated low-privileged user on Devolutions Server.
Which versions of Devolutions Server are affected by CVE-2026-17570?
This vulnerability primarily affects Devolutions Server versions 2026.2.4.0 through 2026.2.12.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.