PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9246 Devolutions CVE debrief

CVE-2026-9246 is an improper access control vulnerability in Devolutions Server's entry documentation and attachment features. An authenticated user with vault read access can retrieve documentation and attachments of sealed entries via a crafted API request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3, indicating a medium severity vulnerability.

Vendor
Devolutions
Product
Devolutions Server
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Users of Devolutions Server, particularly those with vault read access, should be aware of this vulnerability. Administrators of Devolutions Server should apply patches or mitigations as recommended by the vendor. Security teams should review the vulnerability and implement additional security measures to prevent exploitation.

Technical summary

The vulnerability, CVE-2026-9246, is caused by improper access control in the entry documentation and attachment features of Devolutions Server. This allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. The affected versions are 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3, indicating a medium severity vulnerability.

Defensive priority

Medium priority due to the CVSS score of 4.3 and the potential for authenticated users to exploit this vulnerability.

Recommended defensive actions

  • Apply patches or updates provided by Devolutions to address the vulnerability.
  • Restrict access to sensitive features and data within Devolutions Server.
  • Monitor for suspicious activity related to API requests.
  • Implement additional security measures such as multi-factor authentication.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-05-22T16:16:25.653Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. This information is based on the NVD entry and the CVE record. The vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The CVSS score is 4.3, indicating a medium severity vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T16:16:25.653Z and has not been modified since then. The NVD entry is currently Analyzed.