Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0024/ |
|
History
Thu, 16 Jul 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Devolutions Server Recovery Kit Exposes Azure Key Vault Secrets |
Wed, 15 Jul 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions server |
|
| Vendors & Products |
Devolutions
Devolutions server |
Wed, 15 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 14 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected. | |
| Weaknesses | CWE-200 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published: 2026-07-14T18:09:46.308Z
Updated: 2026-07-15T14:43:07.544Z
Reserved: 2026-07-13T18:21:40.280Z
Link: CVE-2026-15642
Updated: 2026-07-15T14:42:53.202Z
No data.
No data.