Devolutions Server Version 2026.3.7.0 (September 29, 2026)

Devolutions Server Version 2026.3.7.0 (September 29, 2026)

avatar

If you are using a client (RDM, PowerShell, etc.), version 2026.3 is required for this DVLS version

IMPROVEMENTS

  • Core - Added an option to import legacy roles that were not created during migration, allowing them to be used in role assignments


FIXES

  • SECURITY Core - Fixed a security issue where the legacy partial login endpoint accepted and retained client-supplied session identifiers after authentication
  • SECURITY Core - Fixed a SQL injection vulnerability in the database backup path setting
  • SECURITY Core - Fixed an issue where low-privileged users could restore and permanently delete vault attachments through attachment history
  • SECURITY Core - Fixed authentication and session tokens being stored unencrypted in the database
  • SECURITY Core - Fixed integration secrets in data source settings being visible to users without administrative permissions
  • SECURITY Core - Fixed missing access controls that allowed users without the required permissions to read or save System Vault entries
  • SECURITY Core - Fixed the Microsoft Entra ID application secret being exposed in URL query strings when retrieving groups and role templates
  • SECURITY Gateway - Fixed a security issue where any authenticated user could obtain a network scan token and access internal network information
  • SECURITY PAM - Fixed domain controller detection occurring before the Devolutions Gateway ruleset was enforced, allowing network traffic to bypass the ruleset and gateway logging
  • SECURITY PAM - Fixed the legacy WinRM client mode ignoring the "Skip TLS certificate validation" setting and always skipping certificate validation for HTTPS hosts
  • Core - Fixed an error when filtering or sorting Administration logs by user on SQL Server databases using case-sensitive collation
  • Core - Fixed the "dvls-admin" user on Basic installations being able to bypass the required password change by closing the browser
  • Core - Fixed the Public API returning a 404 error instead of a 400 error for malformed request bodies
  • Core - Fixed users without System Vault entry edit permission being able to edit System Vault entries through their regular entry permissions
  • Gateway - Fixed an issue where "Force Gateway rulesets" could be bypassed when a connection explicitly targeted a physical gateway
  • Gateway - Fixed rejected Devolutions Gateway certificates being incorrectly reported as unreachable domain controllers in Active Directory domain configurations
  • PAM - Fixed Active Directory and Windows providers being unable to use a Devolutions Gateway in LDAPS mode with an already trusted certificate
  • Web - Fixed notification settings not being saved when exactly two available actions were selected
  • Web - Fixed renamed custom field titles not being retained when confirmed with the checkmark in the entry edit dialog
  • Web - Fixed trailing spaces being saved in tags and "Exact expression" notification subscription filters despite appearing to be removed in the interface
  • Web - Multiple UI fixes


** CONSOLE RELEASE NOTES **

IMPROVEMENTS

  • Minor update

All Comments (0)