Devolutions / Devolutions Server
112 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-17570 | Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credentia… | MEDIUM | 4.3 | Jul 27, 2026 |
| CVE-2026-17569 | Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored… | MEDIUM | 4.3 | Jul 27, 2026 |
| CVE-2026-17568 | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group… | HIGH | 8.8 | Jul 27, 2026 |
| CVE-2026-15058 | Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user'… | LOW | 3.1 | Jul 14, 2026 |
| CVE-2026-15642 | Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an at… | LOW | 3.3 | Jul 14, 2026 |
| CVE-2026-15641 | Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve… | HIGH | 7.1 | Jul 14, 2026 |
| CVE-2026-15637 | Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged… | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-14536 | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypas… | HIGH | 8.8 | Jul 6, 2026 |
| CVE-2026-12755 | Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroup… | LOW | 2.7 | Jun 25, 2026 |
| CVE-2026-12105 | Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited perm… | MEDIUM | 6.5 | Jun 16, 2026 |
| CVE-2026-12117 | Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login e… | MEDIUM | 4.3 | Jun 16, 2026 |
| CVE-2026-11890 | Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery s… | MEDIUM | 4.3 | Jun 16, 2026 |
| CVE-2026-10544 | Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with wr… | MEDIUM | 6.5 | Jun 8, 2026 |
| CVE-2026-10787 | Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user gr… | MEDIUM | 4.3 | Jun 8, 2026 |
| CVE-2026-10786 | Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials… | MEDIUM | 6.5 | Jun 8, 2026 |
| CVE-2026-9522 | Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative pr… | MEDIUM | 5.4 | Jun 2, 2026 |
| CVE-2026-9590 | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privile… | MEDIUM | 5.3 | Jun 2, 2026 |
| CVE-2026-7325 | Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication mater… | HIGH | 7.1 | May 22, 2026 |
| CVE-2026-9251 | Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-en… | MEDIUM | 5.4 | May 22, 2026 |
| CVE-2026-5171 | Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required p… | MEDIUM | 4.3 | May 22, 2026 |
| CVE-2026-8477 | Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access… | LOW | 2.7 | May 22, 2026 |
| CVE-2026-9246 | Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retriev… | MEDIUM | 4.3 | May 22, 2026 |
| CVE-2026-9224 | Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attrib… | MEDIUM | 4.3 | May 22, 2026 |
| CVE-2026-9249 | Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password chang… | LOW | 3.1 | May 22, 2026 |
| CVE-2026-9245 | Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to a… | MEDIUM | 5.0 | May 22, 2026 |
Showing 1 to 25 of 112 CVEs