PatchSiren

Devolutions CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Devolutions CVE published 2026-07-27

CVE-2026-17570

CVE-2026-17570 describes an Improper access control vulnerability in Devolutions Server PAM password history endpoints. An authenticated low-privileged user can disclose plaintext credential secrets via crafted API requests. This issue affects Devolutions Server 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability allows an attacker to access sensitive information with relatively [truncated]

MEDIUM Devolutions CVE published 2026-07-27

CVE-2026-17569

CVE-2026-17569 is an improper access control vulnerability in the NetBox synchronizer of Devolutions Server. An authenticated user with view-only permission can obtain a stored API token via the partial connection endpoint. This issue affects Devolutions Server versions 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability could potentially lead to unauthorized access or data breac [truncated]

HIGH Devolutions CVE published 2026-07-27

CVE-2026-17568

CVE-2026-17568 is an improper access control vulnerability in Devolutions Server. An authenticated non-administrative user with user-group membership management permission can escalate privileges to administrator via a crafted API request. This issue affects Devolutions Server 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. The vulnerability has a high impact on the security of the affected sy [truncated]

MEDIUM Devolutions CVE published 2026-07-24

CVE-2026-16802

A local actor with file system access can read secret values via secret variables stored in cleartext on disk when no vault is selected in Devolutions PowerShell Universal 2026.2.2 and earlier. This vulnerability affects users of Devolutions PowerShell Universal 2026.2.2 and earlier who store sensitive information in secret variables. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The [truncated]

HIGH Devolutions CVE published 2026-07-24

CVE-2026-16801

CVE-2026-16801 is a high-severity vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. It allows authenticated users with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file. This vulnerability has a CVSS score of 8.8 and a CVSS severity of HIGH. Administrators and users [truncated]

HIGH Devolutions CVE published 2026-07-24

CVE-2026-16800

CVE-2026-16800 is a high-severity vulnerability in Devolutions PowerShell Universal, allowing authenticated users with schedule creation permissions to inject arbitrary PowerShell code. This issue affects versions 2026.2.2 and earlier. The vulnerability exists in the schedule feature, where an authenticated user can execute arbitrary PowerShell code by crafting schedule parameter names that are concatenat [truncated]

MEDIUM Devolutions CVE published 2026-07-24

CVE-2026-16799

CVE-2026-16799 is an improper access control vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties due to missing server-side authorization checks. This issue could potentially allow unauthorized access and modifications, impacting the security of the affected systems.

MEDIUM Devolutions CVE published 2026-07-24

CVE-2026-16798

CVE-2026-16798 is an Insertion of sensitive information into sent data vulnerability in Devolutions PowerShell Universal 2026.2.2 and earlier. The vulnerability allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token. This type of vulnerability can potentially allow attackers to g [truncated]

HIGH Devolutions CVE published 2026-07-14

CVE-2026-15641

CVE-2026-15641 is an improper authorization vulnerability in Devolutions Server versions 2026.2.11 and 2026.1.22. An authenticated low-privileged user can approve their own pending access requests by directly calling the request status endpoint, bypassing the required approver review. This vulnerability has a high CVSS score of 7.1 and is considered a High severity vulnerability. Users of Devolutions Serv [truncated]

HIGH Devolutions CVE published 2026-07-14

CVE-2026-15637

CVE-2026-15637 is an improper authorization vulnerability in Devolutions Server 2026.2.11 and 2026.1.22. The PAM SSH key and certificate retrieval endpoints allow an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier. This vulnerability has a high CVSS score of 7.5 and is classified as HIGH se [truncated]

LOW Devolutions CVE published 2026-07-14

CVE-2026-15058

CVE-2026-15058 is an improper authorization vulnerability in Devolutions Server, specifically affecting versions 2026.2.11 and 2026.1.22. An authenticated user can delete another user's messages via direct object reference to the message identifier. This issue has a CVSS score of 3.1 and is classified as LOW severity. The vulnerability allows an attacker to bypass authorization checks, potentially leading [truncated]

HIGH Devolutions CVE published 2026-07-06

CVE-2026-14536

CVE-2026-14536 is an authentication bypass vulnerability in Devolutions Server 2026.2.9.0 due to improper enforcement of a mandatory multi-factor authentication policy. An attacker with valid user credentials can bypass the MFA Required policy without completing multi-factor authentication when the server encounters an invalid default MFA value. This issue arises from the improper enforcement of a mandato [truncated]

HIGH Devolutions CVE published 2026-06-26

CVE-2026-13372

CVE-2026-13372 is a high-severity vulnerability in Devolutions Remote Desktop Manager, affecting versions 2026.2.5 through 2026.2.11. An authenticated attacker with write access to a shared workspace can execute a PowerShell script in another user's context due to incorrect link resolution by display name in the custom PowerShell VPN editor. This issue arises from a display name collision with an existing [truncated]

LOW Devolutions CVE published 2026-06-25

CVE-2026-12755

CVE-2026-12755 is a low-severity vulnerability in Devolutions Server versions 2026.2.4.0 through 2026.2.7.0. The issue lies in the PAM AD discovery endpoints, where improper input validation allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host. This results in the exposure of PAM provider credentials as an NTLMv2 challenge-resp [truncated]

HIGH Devolutions CVE published 2026-06-17

CVE-2026-10696

A vulnerability in Devolutions UniGetUI allows a WinGet community catalog contributor to execute an attacker-controlled installer via a crafted catalog package. This occurs because the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier incorrectly resolves names or references, allowing a WinGet community catalog contributor to correlate an installed application with an unrelated, attacker-control [truncated]

MEDIUM Devolutions CVE published 2026-06-16

CVE-2026-12117

CVE-2026-12117 is an improper access control vulnerability in the social login connection endpoint of Devolutions Server 2026.2.5. An authenticated vault member can exploit this vulnerability to enumerate social login entry metadata to which they are not authorized via a crafted API request. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-200. The CVE was published on [cveP [truncated]

MEDIUM Devolutions CVE published 2026-06-16

CVE-2026-12105

CVE-2026-12105 is an improper access control vulnerability in Devolutions Server versions 2026.2.5 and 2026.1.21. An authenticated user can exploit this vulnerability to access attachments by duplicating a folder and inheriting permissions.

MEDIUM Devolutions CVE published 2026-06-16

CVE-2026-11890

CVE-2026-11890 is an Improper access control vulnerability affecting Devolutions Server versions 2026.2.5 and 2026.1.21. The vulnerability allows an authenticated user to retrieve account discovery scan results. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11890) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-11890).

MEDIUM Devolutions CVE published 2026-06-16

CVE-2026-12162

CVE-2026-12162 is an improper host validation vulnerability in the social login autofill feature of Devolutions Remote Desktop Manager 2026.2.8. This vulnerability allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.

HIGH Devolutions CVE published 2026-06-16

CVE-2026-12161

CVE-2026-12161 is an improper input validation vulnerability in Devolutions Remote Desktop Manager 2026.2.7. An authenticated user with permission to create or modify a shared SSH entry can execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.

MEDIUM Devolutions CVE published 2026-06-12

CVE-2026-8694

CVE-2026-8694 is a MEDIUM-severity vulnerability (CVSS Score: 5.3) affecting Devolutions PowerShell Universal 2026.1.7 and earlier. The vulnerability is caused by improper access control, allowing an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.

MEDIUM Devolutions CVE published 2026-06-08

CVE-2026-10787

CVE-2026-10787 is a medium-severity vulnerability in Devolutions Server, allowing an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects Devolutions Server 2026.2.4.0 and 2026.1.20.0 and earlier.

MEDIUM Devolutions CVE published 2026-06-08

CVE-2026-10786

CVE-2026-10786 is a MEDIUM-severity vulnerability in Devolutions Server, with a CVSS score of 6.5. The issue, described as improper access control in the ticketing integration settings, allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request.

MEDIUM Devolutions CVE published 2026-06-08

CVE-2026-10544

CVE-2026-10544 is a medium-severity vulnerability in Devolutions Server, which allows an authenticated user with write access to a vault to execute arbitrary commands on systems managed by the affected PAM provider. The issue arises from improper neutralization of special elements in built-in PAM provider password rotation templates.

MEDIUM Devolutions CVE published 2026-05-22

CVE-2026-9251

A vulnerability exists in Devolutions Server, specifically in the entry status management feature. This allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow. Consequently, the user can gain access to an entry's data by submitting a crafted status change request. The affected product deployments should be reviewed for exposure, and owners should be assign [truncated]

LOW Devolutions CVE published 2026-05-22

CVE-2026-9249

A vulnerability was found in Devolutions Server, which allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 3.1 and is classified as LOW severity. Administrators and users of affected versions sh [truncated]

LOW Devolutions CVE published 2026-05-22

CVE-2026-9248

CVE-2026-9248 is an authorization bypass vulnerability in the entry duplication feature of Devolutions Server. An authenticated user with write access to any vault can copy documentation and attachments from an entry in a vault they cannot access via a crafted save request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CV [truncated]

LOW Devolutions CVE published 2026-05-22

CVE-2026-9247

CVE-2026-9247 is a low-severity vulnerability in Devolutions Server, a software solution for managing and securing privileged accounts. The issue lies in the entry export feature, where an authenticated user with export permissions can export a sealed entry without triggering the unseal notification to administrators via a crafted export request. This vulnerability affects Devolutions Server versions 2026 [truncated]

MEDIUM Devolutions CVE published 2026-05-22

CVE-2026-9246

CVE-2026-9246 is an improper access control vulnerability in Devolutions Server's entry documentation and attachment features. An authenticated user with vault read access can retrieve documentation and attachments of sealed entries via a crafted API request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3 [truncated]

MEDIUM Devolutions CVE published 2026-05-22

CVE-2026-9245

CVE-2026-9245 is a medium-severity vulnerability in Devolutions Server, allowing unauthenticated remote attackers to redirect victims to an attacker-controlled domain via a crafted login link due to improper input validation in the external authentication provider flow. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. Users should be aware of this [truncated]

MEDIUM Devolutions CVE published 2026-05-22

CVE-2026-9224

CVE-2026-9224 is a medium-severity vulnerability in Devolutions Server, allowing an authenticated Active Directory user to modify their own profile attributes via a crafted API request due to missing authorization in the user profile update feature. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 4.3 and a sev [truncated]

MEDIUM Devolutions CVE published 2026-05-22

CVE-2026-9223

A vulnerability exists in Devolutions Server 2026.1.16.0 and earlier, where a low-privileged authenticated user can create new vaults via a crafted import request due to missing authorization in the vault import feature. This issue allows unauthorized vault creation, potentially leading to security risks. Users of Devolutions Server 2026.1.16.0 and earlier should apply the vendor's remediation to prevent [truncated]

HIGH Devolutions CVE published 2026-05-22

CVE-2026-9047

CVE-2026-9047 is a HIGH severity vulnerability in Devolutions Server, with a CVSS score of 7.6. The vulnerability is caused by improper handling of factor key state in the multi-factor authentication management feature. This allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. The vulnerability affects Devolution [truncated]

LOW Devolutions CVE published 2026-05-22

CVE-2026-8477

CVE-2026-8477 is a low-severity vulnerability in Devolutions Server that allows authenticated users with access to sealed entries to retrieve sensitive data without triggering audit notifications via crafted API requests. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. The vulnerability has a CVSS score of 2.7, indicating a low severity. Administr [truncated]

HIGH Devolutions CVE published 2026-05-22

CVE-2026-7325

CVE-2026-7325 is an improper authorization vulnerability in Devolutions Server's Active Directory browsing feature. A low-privileged authenticated user can exploit this to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20. [truncated]

MEDIUM Devolutions CVE published 2026-05-12

CVE-2026-5146

## Summary Devolutions Server contains an improper access control vulnerability (CWE-862) in its notification management endpoints. An unauthenticated attacker can modify or delete arbitrary user notification records due to missing session validation. The vulnerability affects Devolutions Server 2026.1.6.0 through 2026.1.15.0 and all versions through 2025.3.19.0. ## Technical Details The vulnerability exi [truncated]

MEDIUM Devolutions CVE published 2026-05-12

CVE-2026-8407

A missing authorization vulnerability in Devolutions Server's Privileged Access Management (PAM) module allows authenticated users with a PAM license but no additional permissions to obtain sensitive authentication material. The flaw, published 2026-05-12 and last modified 2026-05-26, affects Devolutions Server 2026.1.6.0 through 2026.1.11.0 and versions 2025.3.16.0 and earlier. Attackers can extract OTP [truncated]

CRITICAL Devolutions CVE published 2026-03-03

CVE-2026-2590

CVE-2026-2590 is a critical vulnerability in Devolutions Remote Desktop Manager 2025.3.30 and earlier where the "Disable password saving in vaults" setting is not properly enforced in the connection entry component. As described by the vendor and reflected by NVD, this can allow credentials to be stored in vault entries anyway, potentially exposing sensitive information to other users.