Back

MEDIUM

Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation

Published Jun 5, 2025

Description

Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner DEVOLUTIONS
Published Jun 5, 2025
Updated Jun 5, 2025
Reserved Jan 23, 2025

CISA Vulnrichment

Updated Jun 5, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner DEVOLUTIONS
Published Jun 5, 2025
Updated Jun 5, 2025

GitHub

No data