PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7325 Devolutions CVE debrief

CVE-2026-7325 is an improper authorization vulnerability in Devolutions Server's Active Directory browsing feature. A low-privileged authenticated user can exploit this to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.

Vendor
Devolutions
Product
Devolutions Server
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

System administrators and security teams responsible for Devolutions Server installations, particularly those with low-privileged users, should prioritize patching to prevent potential authentication material exposure.

Technical summary

The vulnerability, with a CVSS score of 7.1, allows low-privileged authenticated users to exploit the Active Directory browsing feature. This can lead to obtaining authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. Affected versions include Devolutions Server 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.

Defensive priority

High priority should be given to patching Devolutions Server instances, especially those with exposed Active Directory browsing features or low-privileged user accounts.

Recommended defensive actions

  • Apply patches or updates provided by Devolutions to address the vulnerability
  • Review and restrict access to the Active Directory browsing feature
  • Monitor for suspicious authentication relay attempts
  • Implement additional security measures for PAM provider service accounts
  • Conduct a thorough inventory of affected systems and prioritize patching

Evidence notes

The CVE record was published on 2026-05-22T16:16:21.620Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. Vendor advisory is available at https://devolutions.net/security/advisories/DEVO-2026-0013/

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T16:16:21.620Z and has not been modified since then. The NVD entry is currently Analyzed.