Server
by Devolutions
CVEs (114)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-6741 | Hig | 0.50 | 7.7 | 0.00 | Jul 22, 2025 | Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 2025.2.2.0 through… | ||
| CVE-2025-6523 | Hig | 0.50 | 7.7 | 0.00 | Jul 22, 2025 | Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following… | ||
| CVE-2026-9047 | Hig | 0.49 | 7.6 | 0.00 | May 22, 2026 | Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue… | ||
| CVE-2026-1007 | Hig | 0.49 | 7.6 | 0.00 | Jan 19, 2026 | Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12. | ||
| CVE-2025-2277 | Hig | 0.49 | 7.5 | 0.01 | Mar 13, 2025 | Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking. | ||
| CVE-2024-1764 | Hig | 0.49 | 7.6 | 0.00 | Mar 5, 2024 | Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances | ||
| CVE-2023-5240 | Hig | 0.49 | 7.5 | 0.01 | Oct 13, 2023 | Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request. | ||
| CVE-2021-23924 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files. | ||
| CVE-2026-8497 | Hig | 0.48 | 7.4 | 0.00 | Jul 29, 2026 | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate. | ||
| CVE-2021-28157 | Hig | 0.47 | 7.2 | 0.01 | Apr 14, 2021 | An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete. | ||
| CVE-2026-7325 | Hig | 0.46 | 7.1 | 0.00 | May 22, 2026 | Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. … | ||
| CVE-2025-8312 | Hig | 0.46 | 7.1 | 0.00 | Jul 30, 2025 | Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) : * Devolutions Server… | ||
| CVE-2025-2003 | Hig | 0.46 | 7.1 | 0.00 | Mar 5, 2025 | Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission. | ||
| CVE-2025-5382 | Med | 0.44 | 6.8 | 0.00 | Jun 5, 2025 | Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA. | ||
| CVE-2026-12105 | Med | 0.42 | 6.5 | 0.00 | Jun 16, 2026 | Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions. | ||
| CVE-2026-10786 | Med | 0.42 | 6.5 | 0.00 | Jun 8, 2026 | Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server… | ||
| CVE-2026-10544 | Med | 0.42 | 6.5 | 0.00 | Jun 8, 2026 | Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue… | ||
| CVE-2026-6706 | Med | 0.42 | 6.5 | 0.00 | Apr 28, 2026 | Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through… | ||
| CVE-2026-4927 | Med | 0.42 | 6.5 | 0.00 | Apr 1, 2026 | Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11. | ||
| CVE-2026-3131 | Med | 0.42 | 6.5 | 0.00 | Feb 24, 2026 | Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data. |
- risk 0.50cvss 7.7epss 0.00
Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 2025.2.2.0 through…
- risk 0.50cvss 7.7epss 0.00
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following…
- risk 0.49cvss 7.6epss 0.00
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue…
- risk 0.49cvss 7.6epss 0.00
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.
- risk 0.49cvss 7.5epss 0.01
Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.
- risk 0.49cvss 7.6epss 0.00
Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances
- risk 0.49cvss 7.5epss 0.01
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
- risk 0.48cvss 7.4epss 0.00
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
- risk 0.47cvss 7.2epss 0.01
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
- risk 0.46cvss 7.1epss 0.00
Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. …
- risk 0.46cvss 7.1epss 0.00
Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) : * Devolutions Server…
- risk 0.46cvss 7.1epss 0.00
Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.
- risk 0.44cvss 6.8epss 0.00
Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.
- risk 0.42cvss 6.5epss 0.00
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.
- risk 0.42cvss 6.5epss 0.00
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server…
- risk 0.42cvss 6.5epss 0.00
Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue…
- risk 0.42cvss 6.5epss 0.00
Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through…
- risk 0.42cvss 6.5epss 0.00
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.
- risk 0.42cvss 6.5epss 0.00
Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.
Page 2 of 6