PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8477 Devolutions CVE debrief

CVE-2026-8477 is a low-severity vulnerability in Devolutions Server that allows authenticated users with access to sealed entries to retrieve sensitive data without triggering audit notifications via crafted API requests. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 2.7, indicating a low severity. Administrators and users of Devolutions Server, especially those with access to sealed entries, should be aware of this vulnerability and take necessary precautions.

Vendor
Devolutions
Product
Devolutions Server
CVSS
LOW 2.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Administrators and users of Devolutions Server, especially those with access to sealed entries, should be aware of this vulnerability and take necessary precautions. This includes reviewing and updating Devolutions Server to a version outside the affected range, restricting access to sealed entries to only necessary personnel, monitoring API requests for suspicious activity, and implementing additional logging and auditing for sensitive data retrievals.

Technical summary

The vulnerability is caused by improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature of Devolutions Server. An authenticated user with access to a sealed entry can retrieve its sensitive data without triggering the unseal audit notification via a crafted API request. The CVSS score for this vulnerability is 2.7, indicating a low severity. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.

Defensive priority

Low

Recommended defensive actions

  • Review and update Devolutions Server to a version outside the affected range
  • Restrict access to sealed entries to only necessary personnel
  • Monitor API requests for suspicious activity
  • Implement additional logging and auditing for sensitive data retrievals
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-05-22T16:16:22.107Z and was last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. This information is based on the supplied source corpus. To verify, defenders should review the official CVE record and NVD entry for any updates or changes. The evidence is limited to publicly available data and may not reflect the full scope of the vulnerability or its impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T16:16:22.107Z and has not been modified since then. The NVD entry is currently Analyzed.