PatchSiren

Devolutions CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Devolutions CVE published 2026-09-15

CVE-2026-13327

CVE-2026-13327 is a high-severity vulnerability in Devolutions Server, allowing a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate due to improper certificate validation on LDAPS connections to Active Directory. The vulnerability affects Devolutions Server 2026.2.16 and earlier, and defenders should verify exposure, assess impact [truncated]

MEDIUM Devolutions CVE published 2026-09-15

CVE-2026-90971

A Server-Side Request Forgery (SSRF) vulnerability exists in the VMware synchronization feature of Devolutions Server versions 2026.2.16 and earlier. This allows a low-privileged authenticated user to obtain other users' credentials and access internal or cloud-metadata network endpoints by submitting a crafted connection definition for datacenter discovery.

MEDIUM Devolutions CVE published 2026-09-15

CVE-2026-90969

CVE-2026-90969 Improper access control in Devolutions Server allows authenticated users lacking view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters. The vulnerability exists in Devolutions Server 2026.2.16 and earlier, posing a medium-severity risk. Administrators and users with access to the vault entry listing feature sho [truncated]

MEDIUM Devolutions CVE published 2026-09-15

CVE-2026-84850

CVE-2026-84850 Improper certificate validation in Devolutions Server allows network-positioned attackers to intercept and tamper with outbound TLS connections. Defenders should assess exposure by reviewing current deployments, prioritize remediation based on risk, and verify affected versions and scope to ensure comprehensive mitigation. This involves confirming whether affected product deployments exist, [truncated]

HIGH Devolutions CVE published 2026-07-29

CVE-2026-8497

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T18:16:58.787Z and has not been modified since then. The improper certificate validation vulnerability in Devolutions Password Manager affects versions 2026.2.1.0 and earlier on Android, iOS, and macOS, allowing an adjacent-network attacker to intercept and modify sensitive information via a forge [truncated]

MEDIUM Devolutions CVE published 2026-07-27

CVE-2026-17570

CVE-2026-17570 describes an Improper access control vulnerability in Devolutions Server PAM password history endpoints. An authenticated low-privileged user can disclose plaintext credential secrets via crafted API requests. This issue affects Devolutions Server 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability allows an attacker to access sensitive information with relatively [truncated]

MEDIUM Devolutions CVE published 2026-07-27

CVE-2026-17569

CVE-2026-17569 is an improper access control vulnerability in the NetBox synchronizer of Devolutions Server. An authenticated user with view-only permission can obtain a stored API token via the partial connection endpoint. This issue affects Devolutions Server versions 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability could potentially lead to unauthorized access or data breac [truncated]

HIGH Devolutions CVE published 2026-07-27

CVE-2026-17568

CVE-2026-17568 is an improper access control vulnerability in Devolutions Server. An authenticated non-administrative user with user-group membership management permission can escalate privileges to administrator via a crafted API request. This issue affects Devolutions Server 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability has a high impact on the security of the affected sy [truncated]

MEDIUM Devolutions CVE published 2026-07-24

CVE-2026-16802

A local actor with file system access can read secret values via secret variables stored in cleartext on disk when no vault is selected in Devolutions PowerShell Universal 2026.2.2 and earlier. This vulnerability affects users of Devolutions PowerShell Universal 2026.2.2 and earlier who store sensitive information in secret variables. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The [truncated]

HIGH Devolutions CVE published 2026-07-24

CVE-2026-16801

CVE-2026-16801 is a high-severity vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. It allows authenticated users with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file. This vulnerability has a CVSS score of 8.8 and a CVSS severity of HIGH. Administrators and users [truncated]

HIGH Devolutions CVE published 2026-07-24

CVE-2026-16800

CVE-2026-16800 is a high-severity vulnerability in Devolutions PowerShell Universal, allowing authenticated users with schedule creation permissions to inject arbitrary PowerShell code. This issue affects versions 2026.2.2 and earlier. The vulnerability exists in the schedule feature, where an authenticated user can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenat [truncated]

MEDIUM Devolutions CVE published 2026-07-24

CVE-2026-16799

CVE-2026-16799 is an improper access control vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties due to missing server-side authorization checks. This issue could potentially allow unauthorized access and modifications, impacting the security of the affected systems.

MEDIUM Devolutions CVE published 2026-07-24

CVE-2026-16798

CVE-2026-16798 is an Insertion of sensitive information into sent data vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. This type of vulnerability can potentially allow attackers to g [truncated]

HIGH Devolutions CVE published 2026-07-14

CVE-2026-15641

CVE-2026-15641 is an improper authorization vulnerability in Devolutions Server versions 2026.2.11 and 2026.1.22. An authenticated low-privileged user can approve their own pending access requests by directly calling the request status endpoint, bypassing the required approver review. This vulnerability has a high CVSS score of 7.1 and is considered a High severity vulnerability. Users of Devolutions Serv [truncated]

HIGH Devolutions CVE published 2026-07-14

CVE-2026-15637

CVE-2026-15637 is an improper authorization vulnerability in Devolutions Server 2026.2.11 and 2026.1.22. The PAM SSH key and certificate retrieval endpoints allow an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier. This vulnerability has a high CVSS score of 7.5 and is classified as HIGH se [truncated]

LOW Devolutions CVE published 2026-07-14

CVE-2026-15058

CVE-2026-15058 is an improper authorization vulnerability in Devolutions Server, specifically affecting versions 2026.2.11 and 2026.1.22. An authenticated user can delete another user's messages via direct object reference to the message identifier. This issue has a CVSS score of 3.1 and is classified as LOW severity. The vulnerability allows an attacker to bypass authorization checks, potentially leading [truncated]

HIGH Devolutions CVE published 2026-07-06

CVE-2026-14536

CVE-2026-14536 is an authentication bypass vulnerability in Devolutions Server 2026.2.9.0 due to improper enforcement of a mandatory multi-factor authentication policy. An attacker with valid user credentials can bypass the MFA Required policy without completing multi-factor authentication when the server encounters an invalid default MFA value. This issue arises from the improper enforcement of a mandato [truncated]

HIGH Devolutions CVE published 2026-06-26

CVE-2026-13372

CVE-2026-13372 is a high-severity vulnerability in Devolutions Remote Desktop Manager, affecting versions 2026.2.5 through 2026.2.11. An authenticated attacker with write access to a shared workspace can execute a PowerShell script in another user's context due to incorrect link resolution by display name in the custom PowerShell VPN editor. This issue arises from a display name collision with an existing [truncated]

LOW Devolutions CVE published 2026-06-25

CVE-2026-12755

CVE-2026-12755 is a low-severity vulnerability in Devolutions Server versions 2026.2.4.0 through 2026.2.7.0. The issue lies in the PAM AD discovery endpoints, where improper input validation allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host. This results in the exposure of PAM provider credentials as an NTLMv2 challenge-resp [truncated]

HIGH Devolutions CVE published 2026-06-17

CVE-2026-10696

A vulnerability in Devolutions UniGetUI allows a WinGet community catalog contributor to execute an attacker-controlled installer via a crafted catalog package. This occurs because the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier incorrectly resolves names or references, allowing a WinGet community catalog contributor to correlate an installed application with an unrelated, attacker-control [truncated]

MEDIUM Devolutions CVE published 2026-06-16

CVE-2026-12117

CVE-2026-12117 is an improper access control vulnerability in the social login connection endpoint of Devolutions Server 2026.2.5. An authenticated vault member can exploit this vulnerability to enumerate social login entry metadata to which they are not authorized via a crafted API request. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-200. The CVE was published on [cveP [truncated]

MEDIUM Devolutions CVE published 2026-06-16

CVE-2026-12105

CVE-2026-12105 is an improper access control vulnerability in Devolutions Server versions 2026.2.5 and 2026.1.21. An authenticated user can exploit this vulnerability to access attachments by duplicating a folder and inheriting permissions.

MEDIUM Devolutions CVE published 2026-06-16

CVE-2026-11890

CVE-2026-11890 is an Improper access control vulnerability affecting Devolutions Server versions 2026.2.5 and 2026.1.21. The vulnerability allows an authenticated user to retrieve account discovery scan results. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11890) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-11890).

MEDIUM Devolutions CVE published 2026-06-16

CVE-2026-12162

CVE-2026-12162 is an improper host validation vulnerability in the social login autofill feature of Devolutions Remote Desktop Manager 2026.2.8. This vulnerability allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

HIGH Devolutions CVE published 2026-06-16

CVE-2026-12161

CVE-2026-12161 is an improper input validation vulnerability in Devolutions Remote Desktop Manager 2026.2.7. An authenticated user with permission to create or modify a shared SSH entry can execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.

MEDIUM Devolutions CVE published 2026-06-12

CVE-2026-8694

CVE-2026-8694 is a MEDIUM-severity vulnerability (CVSS Score: 5.3) affecting Devolutions PowerShell Universal 2026.1.7 and earlier. The vulnerability is caused by improper access control, allowing an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.

MEDIUM Devolutions CVE published 2026-06-08

CVE-2026-10787

CVE-2026-10787 is a medium-severity vulnerability in Devolutions Server, allowing an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects Devolutions Server 2026.2.4.0 and 2026.1.20.0 and earlier.

MEDIUM Devolutions CVE published 2026-06-08

CVE-2026-10786

CVE-2026-10786 is a MEDIUM-severity vulnerability in Devolutions Server, with a CVSS score of 6.5. The issue, described as improper access control in the ticketing integration settings, allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request.

MEDIUM Devolutions CVE published 2026-06-08

CVE-2026-10544

CVE-2026-10544 is a medium-severity vulnerability in Devolutions Server, which allows an authenticated user with write access to a vault to execute arbitrary commands on systems managed by the affected PAM provider. The issue arises from improper neutralization of special elements in built-in PAM provider password rotation templates.

MEDIUM Devolutions CVE published 2026-05-22

CVE-2026-9251

A vulnerability exists in Devolutions Server, specifically in the entry status management feature. This allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow. Consequently, the user can gain access to an entry's data by submitting a crafted status change request. The affected product deployments should be reviewed for exposure, and owners should be assign [truncated]