Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.
History

Thu, 16 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Devolutions Server Recovery Kit Exposes Azure Key Vault Secrets

Wed, 15 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is selected.
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2026-07-14T18:09:46.308Z

Updated: 2026-07-15T14:43:07.544Z

Reserved: 2026-07-13T18:21:40.280Z

Link: CVE-2026-15642

cve-icon Vulnrichment

Updated: 2026-07-15T14:42:53.202Z

cve-icon NVD

No data.

cve-icon Redhat

No data.