VYPR

Server

by Devolutions

CVEs (96)

  • CVE-2023-5240HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.

  • CVE-2021-23924HigApr 1, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.

  • CVE-2021-28157HigApr 14, 2021
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.

  • CVE-2026-7325HigMay 22, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. …

  • CVE-2025-8312HigJul 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) : * Devolutions Server…

  • CVE-2025-2003HigMar 5, 2025
    risk 0.46cvss 7.1epss 0.00

    Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.

  • CVE-2025-5382MedJun 5, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.

  • CVE-2026-10786MedJun 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server…

  • CVE-2026-10544MedJun 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue…

  • CVE-2026-6706MedApr 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through…

  • CVE-2026-4927MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

  • CVE-2025-13683MedNov 28, 2025
    risk 0.42cvss 6.5epss 0.00

    Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.

  • CVE-2025-12808MedNov 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through…

  • CVE-2025-4493MedMay 28, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions :  * Devolutions Server 2025.1.3.0 through…

  • CVE-2025-2278MedMar 13, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID.

  • CVE-2024-12196MedDec 4, 2024
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.

  • CVE-2024-6512MedSep 25, 2024
    risk 0.42cvss 6.5epss 0.00

    Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.

  • CVE-2024-5072MedMay 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.

  • CVE-2023-6588MedDec 7, 2023
    risk 0.42cvss 6.5epss 0.01

    Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.

  • CVE-2023-5575MedOct 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.

Page 2 of 5