PatchSiren cyber security CVE debrief
CVE-2026-9246 Devolutions CVE debrief
CVE-2026-9246 is an improper access control vulnerability in Devolutions Server's entry documentation and attachment features. An authenticated user with vault read access can retrieve documentation and attachments of sealed entries via a crafted API request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3, indicating a medium severity vulnerability.
- Vendor
- Devolutions
- Product
- Devolutions Server
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
Users of Devolutions Server, particularly those with vault read access, should be aware of this vulnerability. Administrators of Devolutions Server should apply patches or mitigations as recommended by the vendor. Security teams should review the vulnerability and implement additional security measures to prevent exploitation.
Technical summary
The vulnerability, CVE-2026-9246, is caused by improper access control in the entry documentation and attachment features of Devolutions Server. This allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. The affected versions are 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3, indicating a medium severity vulnerability.
Defensive priority
Medium priority due to the CVSS score of 4.3 and the potential for authenticated users to exploit this vulnerability.
Recommended defensive actions
- Apply patches or updates provided by Devolutions to address the vulnerability.
- Restrict access to sensitive features and data within Devolutions Server.
- Monitor for suspicious activity related to API requests.
- Implement additional security measures such as multi-factor authentication.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-05-22T16:16:25.653Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. This information is based on the NVD entry and the CVE record. The vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The CVSS score is 4.3, indicating a medium severity vulnerability.
Official resources
-
CVE-2026-9246 CVE record
CVE.org
-
CVE-2026-9246 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T16:16:25.653Z and has not been modified since then. The NVD entry is currently Analyzed.