CVE-2026-9247
LOWDescription
Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier
Is your site exposed to CVE-2026-9247?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| devolutions | devolutions_server |
| devolutions | devolutions_server |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-9247? +
How severe is CVE-2026-9247? +
What products are affected by CVE-2026-9247? +
How do I check if I'm vulnerable to CVE-2026-9247? +
Related Vulnerabilities
: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: …
Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, …
Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit …
Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs …
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent …
phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful …