If you are using a client (RDM, PowerShell, etc.), version 2026.3 is required for this DVLS version
IMPROVEMENTS
- Core - Added an option to import legacy roles that were not created during migration, allowing them to be used in role assignments
FIXES
- SECURITY Core - Fixed a security issue where the legacy partial login endpoint accepted and retained client-supplied session identifiers after authentication
- SECURITY Core - Fixed a SQL injection vulnerability in the database backup path setting
- SECURITY Core - Fixed an issue where low-privileged users could restore and permanently delete vault attachments through attachment history
- SECURITY Core - Fixed authentication and session tokens being stored unencrypted in the database
- SECURITY Core - Fixed integration secrets in data source settings being visible to users without administrative permissions
- SECURITY Core - Fixed missing access controls that allowed users without the required permissions to read or save System Vault entries
- SECURITY Core - Fixed the Microsoft Entra ID application secret being exposed in URL query strings when retrieving groups and role templates
- SECURITY Gateway - Fixed a security issue where any authenticated user could obtain a network scan token and access internal network information
- SECURITY PAM - Fixed domain controller detection occurring before the Devolutions Gateway ruleset was enforced, allowing network traffic to bypass the ruleset and gateway logging
- SECURITY PAM - Fixed the legacy WinRM client mode ignoring the "Skip TLS certificate validation" setting and always skipping certificate validation for HTTPS hosts
- Core - Fixed an error when filtering or sorting Administration logs by user on SQL Server databases using case-sensitive collation
- Core - Fixed the "dvls-admin" user on Basic installations being able to bypass the required password change by closing the browser
- Core - Fixed the Public API returning a 404 error instead of a 400 error for malformed request bodies
- Core - Fixed users without System Vault entry edit permission being able to edit System Vault entries through their regular entry permissions
- Gateway - Fixed an issue where "Force Gateway rulesets" could be bypassed when a connection explicitly targeted a physical gateway
- Gateway - Fixed rejected Devolutions Gateway certificates being incorrectly reported as unreachable domain controllers in Active Directory domain configurations
- PAM - Fixed Active Directory and Windows providers being unable to use a Devolutions Gateway in LDAPS mode with an already trusted certificate
- Web - Fixed notification settings not being saved when exactly two available actions were selected
- Web - Fixed renamed custom field titles not being retained when confirmed with the checkmark in the entry edit dialog
- Web - Fixed trailing spaces being saved in tags and "Exact expression" notification subscription filters despite appearing to be removed in the interface
- Web - Multiple UI fixes
** CONSOLE RELEASE NOTES **
IMPROVEMENTS