{"id":"CVE-2025-12808","title":"Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure.\n\n\n\n\n\nThis issue affects the following versions :\n\n  *…","summary":"Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure.\n\n\n\n\n\nThis issue affects the following versions :\n\n  *…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-284"],"vendor":"devolutions","product":"devolutions_server","affected":["devolutions_server < 2025.2.17.0","devolutions_server >= 2025.3.2.0, < 2025.3.6.0"],"patched":["devolutions_server 2025.3.6.0"],"published":"2025-11-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-12808","references":[{"url":"https://devolutions.net/security/advisories/DEVO-2025-0016","label":"security@devolutions.net"}],"tags":["nvd"],"epss":0.0043,"epssPercentile":0.35215,"ingestedAt":"2026-10-07T21:54:14.964Z","slug":"CVE-2025-12808","body":"## Overview\n\nImproper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure.\n\n\n\n\n\nThis issue affects the following versions :\n\n  *  Devolutions Server 2025.3.2.0 through 2025.3.5.0\n  *  \n\nDevolutions Server 2025.2.15.0 and earlier\n\n## Affected\n\n- `devolutions_server < 2025.2.17.0`\n- `devolutions_server >= 2025.3.2.0, < 2025.3.6.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `devolutions_server 2025.3.6.0`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}