PatchSiren cyber security CVE debrief
CVE-2026-9224 Devolutions CVE debrief
CVE-2026-9224 is a medium-severity vulnerability in Devolutions Server, allowing an authenticated Active Directory user to modify their own profile attributes via a crafted API request due to missing authorization in the user profile update feature. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Administrators and users of Devolutions Server, especially those with Active Directory integration, should be aware of this vulnerability and take necessary actions to protect their systems.
- Vendor
- Devolutions
- Product
- Devolutions Server
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
Administrators and users of Devolutions Server, especially those with Active Directory integration, should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing and applying patches, restricting API access, and monitoring system logs for suspicious activity.
Technical summary
The vulnerability exists in the user profile update feature of Devolutions Server. An authenticated Active Directory user can exploit this issue by sending a crafted API request to modify their own profile attributes. This affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The issue is caused by missing authorization in the user profile update feature, allowing authenticated users to make unauthorized changes to their profiles.
Defensive priority
Medium priority due to the potential for authenticated users to modify their own profiles, which could lead to unauthorized changes.
Recommended defensive actions
- Apply the latest patches or updates provided by Devolutions to address this vulnerability.
- Review and restrict API access for authenticated users to prevent unauthorized profile modifications.
- Monitor user profile changes and system logs for suspicious activity.
- Consider implementing additional security measures such as multi-factor authentication and role-based access control.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-05-22T16:16:25.083Z and was last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. This vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The issue allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request due to missing authorization in the user profile update feature. Evidence limits suggest verifying affected deployments and reviewing official advisories for mitigation and fix information.
Official resources
-
CVE-2026-9224 CVE record
CVE.org
-
CVE-2026-9224 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T16:16:25.083Z and has not been modified since then. The NVD entry is currently Analyzed.