Devolutions / Server
96 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-100289 | Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generat… | MEDIUM | 5.0 | Sep 29, 2026 |
| CVE-2026-100288 | Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to… | HIGH | 7.2 | Sep 29, 2026 |
| CVE-2026-100287 | Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently del… | MEDIUM | 5.4 | Sep 29, 2026 |
| CVE-2026-100286 | Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose… | MEDIUM | 6.5 | Sep 29, 2026 |
| CVE-2026-93332 | Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create,… | MEDIUM | 5.4 | Sep 29, 2026 |
| CVE-2026-93330 | Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions… | MEDIUM | 4.3 | Sep 29, 2026 |
| CVE-2026-13327 | Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to in… | HIGH | 8.3 | Sep 15, 2026 |
| CVE-2026-84850 | Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a… | MEDIUM | 4.8 | Sep 15, 2026 |
| CVE-2026-90969 | Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password p… | MEDIUM | 6.5 | Sep 15, 2026 |
| CVE-2026-90971 | Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user… | MEDIUM | 6.5 | Sep 15, 2026 |
| CVE-2026-17570 | Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credentia… | MEDIUM | 4.3 | Jul 27, 2026 |
| CVE-2026-17569 | Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored… | MEDIUM | 4.3 | Jul 27, 2026 |
| CVE-2026-17568 | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group… | HIGH | 8.8 | Jul 27, 2026 |
| CVE-2026-15058 | Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user'… | LOW | 3.1 | Jul 14, 2026 |
| CVE-2026-15642 | Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an at… | LOW | 3.3 | Jul 14, 2026 |
| CVE-2026-15641 | Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve… | HIGH | 7.1 | Jul 14, 2026 |
| CVE-2026-15637 | Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged… | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-14536 | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypas… | HIGH | 8.8 | Jul 6, 2026 |
| CVE-2026-12755 | Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroup… | LOW | 2.7 | Jun 25, 2026 |
| CVE-2026-10544 | Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with wr… | MEDIUM | 6.5 | Jun 8, 2026 |
| CVE-2026-10787 | Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user gr… | MEDIUM | 4.3 | Jun 8, 2026 |
| CVE-2026-10786 | Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials… | MEDIUM | 6.5 | Jun 8, 2026 |
| CVE-2026-9522 | Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative pr… | MEDIUM | 5.4 | Jun 2, 2026 |
| CVE-2026-9590 | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privile… | MEDIUM | 5.3 | Jun 2, 2026 |
| CVE-2026-7325 | Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication mater… | HIGH | 7.1 | May 22, 2026 |
Showing 1 to 25 of 96 CVEs