PatchSiren cyber security CVE debrief
CVE-2026-7325 Devolutions CVE debrief
CVE-2026-7325 is an improper authorization vulnerability in Devolutions Server's Active Directory browsing feature. A low-privileged authenticated user can exploit this to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.
- Vendor
- Devolutions
- Product
- Devolutions Server
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
System administrators and security teams responsible for Devolutions Server installations, particularly those with low-privileged users, should prioritize patching to prevent potential authentication material exposure.
Technical summary
The vulnerability, with a CVSS score of 7.1, allows low-privileged authenticated users to exploit the Active Directory browsing feature. This can lead to obtaining authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. Affected versions include Devolutions Server 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.
Defensive priority
High priority should be given to patching Devolutions Server instances, especially those with exposed Active Directory browsing features or low-privileged user accounts.
Recommended defensive actions
- Apply patches or updates provided by Devolutions to address the vulnerability
- Review and restrict access to the Active Directory browsing feature
- Monitor for suspicious authentication relay attempts
- Implement additional security measures for PAM provider service accounts
- Conduct a thorough inventory of affected systems and prioritize patching
Evidence notes
The CVE record was published on 2026-05-22T16:16:21.620Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. Vendor advisory is available at https://devolutions.net/security/advisories/DEVO-2026-0013/
Official resources
-
CVE-2026-7325 CVE record
CVE.org
-
CVE-2026-7325 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T16:16:21.620Z and has not been modified since then. The NVD entry is currently Analyzed.