These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-17570 describes an Improper access control vulnerability in Devolutions Server PAM password history endpoints. An authenticated low-privileged user can disclose plaintext credential secrets via crafted API requests. This issue affects Devolutions Server 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability allows an attacker to access sensitive information with relatively [truncated]
CVE-2026-17569 is an improper access control vulnerability in the NetBox synchronizer of Devolutions Server. An authenticated user with view-only permission can obtain a stored API token via the partial connection endpoint. This issue affects Devolutions Server versions 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability could potentially lead to unauthorized access or data breac [truncated]
CVE-2026-17568 is an improper access control vulnerability in Devolutions Server. An authenticated non-administrative user with user-group membership management permission can escalate privileges to administrator via a crafted API request. This issue affects Devolutions Server 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability has a high impact on the security of the affected sy [truncated]
A local actor with file system access can read secret values via secret variables stored in cleartext on disk when no vault is selected in Devolutions PowerShell Universal 2026.2.2 and earlier. This vulnerability affects users of Devolutions PowerShell Universal 2026.2.2 and earlier who store sensitive information in secret variables. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The [truncated]
CVE-2026-16801 is a high-severity vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. It allows authenticated users with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file. This vulnerability has a CVSS score of 8.8 and a CVSS severity of HIGH. Administrators and users [truncated]
CVE-2026-16800 is a high-severity vulnerability in Devolutions PowerShell Universal, allowing authenticated users with schedule creation permissions to inject arbitrary PowerShell code. This issue affects versions 2026.2.2 and earlier. The vulnerability exists in the schedule feature, where an authenticated user can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenat [truncated]
CVE-2026-16799 is an improper access control vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties due to missing server-side authorization checks. This issue could potentially allow unauthorized access and modifications, impacting the security of the affected systems.
CVE-2026-16798 is an Insertion of sensitive information into sent data vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. This type of vulnerability can potentially allow attackers to g [truncated]
CVE-2026-15641 is an improper authorization vulnerability in Devolutions Server versions 2026.2.11 and 2026.1.22. An authenticated low-privileged user can approve their own pending access requests by directly calling the request status endpoint, bypassing the required approver review. This vulnerability has a high CVSS score of 7.1 and is considered a High severity vulnerability. Users of Devolutions Serv [truncated]
CVE-2026-15637 is an improper authorization vulnerability in Devolutions Server 2026.2.11 and 2026.1.22. The PAM SSH key and certificate retrieval endpoints allow an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier. This vulnerability has a high CVSS score of 7.5 and is classified as HIGH se [truncated]
CVE-2026-15058 is an improper authorization vulnerability in Devolutions Server, specifically affecting versions 2026.2.11 and 2026.1.22. An authenticated user can delete another user's messages via direct object reference to the message identifier. This issue has a CVSS score of 3.1 and is classified as LOW severity. The vulnerability allows an attacker to bypass authorization checks, potentially leading [truncated]
CVE-2026-14536 is an authentication bypass vulnerability in Devolutions Server 2026.2.9.0 due to improper enforcement of a mandatory multi-factor authentication policy. An attacker with valid user credentials can bypass the MFA Required policy without completing multi-factor authentication when the server encounters an invalid default MFA value. This issue arises from the improper enforcement of a mandato [truncated]
CVE-2026-13372 is a high-severity vulnerability in Devolutions Remote Desktop Manager, affecting versions 2026.2.5 through 2026.2.11. An authenticated attacker with write access to a shared workspace can execute a PowerShell script in another user's context due to incorrect link resolution by display name in the custom PowerShell VPN editor. This issue arises from a display name collision with an existing [truncated]
CVE-2026-12755 is a low-severity vulnerability in Devolutions Server versions 2026.2.4.0 through 2026.2.7.0. The issue lies in the PAM AD discovery endpoints, where improper input validation allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host. This results in the exposure of PAM provider credentials as an NTLMv2 challenge-resp [truncated]
A vulnerability in Devolutions UniGetUI allows a WinGet community catalog contributor to execute an attacker-controlled installer via a crafted catalog package. This occurs because the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier incorrectly resolves names or references, allowing a WinGet community catalog contributor to correlate an installed application with an unrelated, attacker-control [truncated]
CVE-2026-12117 is an improper access control vulnerability in the social login connection endpoint of Devolutions Server 2026.2.5. An authenticated vault member can exploit this vulnerability to enumerate social login entry metadata to which they are not authorized via a crafted API request. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-200. The CVE was published on [cveP [truncated]
CVE-2026-12105 is an improper access control vulnerability in Devolutions Server versions 2026.2.5 and 2026.1.21. An authenticated user can exploit this vulnerability to access attachments by duplicating a folder and inheriting permissions.
CVE-2026-11890 is an Improper access control vulnerability affecting Devolutions Server versions 2026.2.5 and 2026.1.21. The vulnerability allows an authenticated user to retrieve account discovery scan results. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11890) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-11890).
CVE-2026-12162 is an improper host validation vulnerability in the social login autofill feature of Devolutions Remote Desktop Manager 2026.2.8. This vulnerability allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.
CVE-2026-12161 is an improper input validation vulnerability in Devolutions Remote Desktop Manager 2026.2.7. An authenticated user with permission to create or modify a shared SSH entry can execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.
CVE-2026-8694 is a MEDIUM-severity vulnerability (CVSS Score: 5.3) affecting Devolutions PowerShell Universal 2026.1.7 and earlier. The vulnerability is caused by improper access control, allowing an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
CVE-2026-10787 is a medium-severity vulnerability in Devolutions Server, allowing an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects Devolutions Server 2026.2.4.0 and 2026.1.20.0 and earlier.
CVE-2026-10786 is a MEDIUM-severity vulnerability in Devolutions Server, with a CVSS score of 6.5. The issue, described as improper access control in the ticketing integration settings, allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request.
CVE-2026-10544 is a medium-severity vulnerability in Devolutions Server, which allows an authenticated user with write access to a vault to execute arbitrary commands on systems managed by the affected PAM provider. The issue arises from improper neutralization of special elements in built-in PAM provider password rotation templates.
A vulnerability exists in Devolutions Server, specifically in the entry status management feature. This allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow. Consequently, the user can gain access to an entry's data by submitting a crafted status change request. The affected product deployments should be reviewed for exposure, and owners should be assign [truncated]
A vulnerability was found in Devolutions Server, which allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 3.1 and is classified as LOW severity. Administrators and users of affected versions sh [truncated]
CVE-2026-9248 is an authorization bypass vulnerability in the entry duplication feature of Devolutions Server. An authenticated user with write access to any vault can copy documentation and attachments from an entry in a vault they cannot access via a crafted save request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CV [truncated]
CVE-2026-9247 is a low-severity vulnerability in Devolutions Server, a software solution for managing and securing privileged accounts. The issue lies in the entry export feature, where an authenticated user with export permissions can export a sealed entry without triggering the unseal notification to administrators via a crafted export request. This vulnerability affects Devolutions Server versions 2026 [truncated]
CVE-2026-9246 is an improper access control vulnerability in Devolutions Server's entry documentation and attachment features. An authenticated user with vault read access can retrieve documentation and attachments of sealed entries via a crafted API request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3 [truncated]
CVE-2026-9245 is a medium-severity vulnerability in Devolutions Server, allowing unauthenticated remote attackers to redirect victims to an attacker-controlled domain via a crafted login link due to improper input validation in the external authentication provider flow. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. Users should be aware of this [truncated]
CVE-2026-9224 is a medium-severity vulnerability in Devolutions Server, allowing an authenticated Active Directory user to modify their own profile attributes via a crafted API request due to missing authorization in the user profile update feature. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3 and a sev [truncated]
A vulnerability exists in Devolutions Server 2026.1.16.0 and earlier, where a low-privileged authenticated user can create new vaults via a crafted import request due to missing authorization in the vault import feature. This issue allows unauthorized vault creation, potentially leading to security risks. Users of Devolutions Server 2026.1.16.0 and earlier should apply the vendor's remediation to prevent [truncated]
CVE-2026-9047 is a HIGH severity vulnerability in Devolutions Server, with a CVSS score of 7.6. The vulnerability is caused by improper handling of factor key state in the multi-factor authentication management feature. This allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. The vulnerability affects Devolution [truncated]
CVE-2026-8477 is a low-severity vulnerability in Devolutions Server that allows authenticated users with access to sealed entries to retrieve sensitive data without triggering audit notifications via crafted API requests. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 2.7, indicating a low severity. Administr [truncated]
CVE-2026-7325 is an improper authorization vulnerability in Devolutions Server's Active Directory browsing feature. A low-privileged authenticated user can exploit this to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20. [truncated]
## Summary Devolutions Server contains an improper access control vulnerability (CWE-862) in its notification management endpoints. An unauthenticated attacker can modify or delete arbitrary user notification records due to missing session validation. The vulnerability affects Devolutions Server 2026.1.6.0 through 2026.1.15.0 and all versions through 2025.3.19.0. ## Technical Details The vulnerability exi [truncated]
A missing authorization vulnerability in Devolutions Server's Privileged Access Management (PAM) module allows authenticated users with a PAM license but no additional permissions to obtain sensitive authentication material. The flaw, published 2026-05-12 and last modified 2026-05-26, affects Devolutions Server 2026.1.6.0 through 2026.1.11.0 and versions 2025.3.16.0 and earlier. Attackers can extract OTP [truncated]
CVE-2026-2590 is a critical vulnerability in Devolutions Remote Desktop Manager 2025.3.30 and earlier where the "Disable password saving in vaults" setting is not properly enforced in the connection entry component. As described by the vendor and reflected by NVD, this can allow credentials to be stored in vault entries anyway, potentially exposing sensitive information to other users.