PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9224 Devolutions CVE debrief

CVE-2026-9224 is a medium-severity vulnerability in Devolutions Server, allowing an authenticated Active Directory user to modify their own profile attributes via a crafted API request due to missing authorization in the user profile update feature. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Administrators and users of Devolutions Server, especially those with Active Directory integration, should be aware of this vulnerability and take necessary actions to protect their systems.

Vendor
Devolutions
Product
Devolutions Server
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Administrators and users of Devolutions Server, especially those with Active Directory integration, should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing and applying patches, restricting API access, and monitoring system logs for suspicious activity.

Technical summary

The vulnerability exists in the user profile update feature of Devolutions Server. An authenticated Active Directory user can exploit this issue by sending a crafted API request to modify their own profile attributes. This affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The issue is caused by missing authorization in the user profile update feature, allowing authenticated users to make unauthorized changes to their profiles.

Defensive priority

Medium priority due to the potential for authenticated users to modify their own profiles, which could lead to unauthorized changes.

Recommended defensive actions

  • Apply the latest patches or updates provided by Devolutions to address this vulnerability.
  • Review and restrict API access for authenticated users to prevent unauthorized profile modifications.
  • Monitor user profile changes and system logs for suspicious activity.
  • Consider implementing additional security measures such as multi-factor authentication and role-based access control.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-05-22T16:16:25.083Z and was last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. This vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The issue allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request due to missing authorization in the user profile update feature. Evidence limits suggest verifying affected deployments and reviewing official advisories for mitigation and fix information.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T16:16:25.083Z and has not been modified since then. The NVD entry is currently Analyzed.