PatchSiren cyber security CVE debrief
CVE-2026-8477 Devolutions CVE debrief
CVE-2026-8477 is a low-severity vulnerability in Devolutions Server that allows authenticated users with access to sealed entries to retrieve sensitive data without triggering audit notifications via crafted API requests. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 2.7, indicating a low severity. Administrators and users of Devolutions Server, especially those with access to sealed entries, should be aware of this vulnerability and take necessary precautions.
- Vendor
- Devolutions
- Product
- Devolutions Server
- CVSS
- LOW 2.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
Administrators and users of Devolutions Server, especially those with access to sealed entries, should be aware of this vulnerability and take necessary precautions. This includes reviewing and updating Devolutions Server to a version outside the affected range, restricting access to sealed entries to only necessary personnel, monitoring API requests for suspicious activity, and implementing additional logging and auditing for sensitive data retrievals.
Technical summary
The vulnerability is caused by improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature of Devolutions Server. An authenticated user with access to a sealed entry can retrieve its sensitive data without triggering the unseal audit notification via a crafted API request. The CVSS score for this vulnerability is 2.7, indicating a low severity. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.
Defensive priority
Low
Recommended defensive actions
- Review and update Devolutions Server to a version outside the affected range
- Restrict access to sealed entries to only necessary personnel
- Monitor API requests for suspicious activity
- Implement additional logging and auditing for sensitive data retrievals
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-05-22T16:16:22.107Z and was last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. This information is based on the supplied source corpus. To verify, defenders should review the official CVE record and NVD entry for any updates or changes. The evidence is limited to publicly available data and may not reflect the full scope of the vulnerability or its impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8477 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8477
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8477 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8477
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://devolutions.net/security/advisories/DEVO-2026-0013/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.