PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8477 Devolutions CVE debrief

CVE-2026-8477 is a low-severity vulnerability in Devolutions Server that allows authenticated users with access to sealed entries to retrieve sensitive data without triggering audit notifications via crafted API requests. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 2.7, indicating a low severity. Administrators and users of Devolutions Server, especially those with access to sealed entries, should be aware of this vulnerability and take necessary precautions.

Vendor
Devolutions
Product
Devolutions Server
CVSS
LOW 2.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Administrators and users of Devolutions Server, especially those with access to sealed entries, should be aware of this vulnerability and take necessary precautions. This includes reviewing and updating Devolutions Server to a version outside the affected range, restricting access to sealed entries to only necessary personnel, monitoring API requests for suspicious activity, and implementing additional logging and auditing for sensitive data retrievals.

Technical summary

The vulnerability is caused by improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature of Devolutions Server. An authenticated user with access to a sealed entry can retrieve its sensitive data without triggering the unseal audit notification via a crafted API request. The CVSS score for this vulnerability is 2.7, indicating a low severity. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier.

Defensive priority

Low

Recommended defensive actions

  • Review and update Devolutions Server to a version outside the affected range
  • Restrict access to sealed entries to only necessary personnel
  • Monitor API requests for suspicious activity
  • Implement additional logging and auditing for sensitive data retrievals
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-05-22T16:16:22.107Z and was last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. This information is based on the supplied source corpus. To verify, defenders should review the official CVE record and NVD entry for any updates or changes. The evidence is limited to publicly available data and may not reflect the full scope of the vulnerability or its impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8477 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8477

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8477 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8477

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.