PatchSiren cyber security CVE debrief
CVE-2026-7325 Devolutions CVE debrief
CVE-2026-7325 is an improper authorization vulnerability in Devolutions Server's Active Directory browsing feature. A low-privileged authenticated user can exploit this to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.
- Vendor
- Devolutions
- Product
- Devolutions Server
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
System administrators and security teams responsible for Devolutions Server installations, particularly those with low-privileged users, should prioritize patching to prevent potential authentication material exposure.
Technical summary
The vulnerability, with a CVSS score of 7.1, allows low-privileged authenticated users to exploit the Active Directory browsing feature. This can lead to obtaining authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. Affected versions include Devolutions Server 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.
Defensive priority
High priority should be given to patching Devolutions Server instances, especially those with exposed Active Directory browsing features or low-privileged user accounts.
Recommended defensive actions
- Apply patches or updates provided by Devolutions to address the vulnerability
- Review and restrict access to the Active Directory browsing feature
- Monitor for suspicious authentication relay attempts
- Implement additional security measures for PAM provider service accounts
- Conduct a thorough inventory of affected systems and prioritize patching
Evidence notes
The CVE record was published on 2026-05-22T16:16:21.620Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. Vendor advisory is available at https://devolutions.net/security/advisories/DEVO-2026-0013/
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7325 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7325
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7325 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7325
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://devolutions.net/security/advisories/DEVO-2026-0013/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.