VYPR

Server

by Devolutions

CVEs (114)

  • CVE-2025-6741HigJul 22, 2025
    risk 0.50cvss 7.7epss 0.00

    Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 2025.2.2.0 through…

  • CVE-2025-6523HigJul 22, 2025
    risk 0.50cvss 7.7epss 0.00

    Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following…

  • CVE-2026-9047HigMay 22, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue…

  • CVE-2026-1007HigJan 19, 2026
    risk 0.49cvss 7.6epss 0.00

    Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.

  • CVE-2025-2277HigMar 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.

  • CVE-2024-1764HigMar 5, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances

  • CVE-2023-5240HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.

  • CVE-2021-23924HigApr 1, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.

  • CVE-2026-8497HigJul 29, 2026
    risk 0.48cvss 7.4epss 0.00

    Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.

  • CVE-2021-28157HigApr 14, 2021
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.

  • CVE-2026-7325HigMay 22, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server. …

  • CVE-2025-8312HigJul 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) : * Devolutions Server…

  • CVE-2025-2003HigMar 5, 2025
    risk 0.46cvss 7.1epss 0.00

    Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.

  • CVE-2025-5382MedJun 5, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.

  • CVE-2026-12105MedJun 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.

  • CVE-2026-10786MedJun 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server…

  • CVE-2026-10544MedJun 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue…

  • CVE-2026-6706MedApr 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through…

  • CVE-2026-4927MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

  • CVE-2026-3131MedFeb 24, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.

Page 2 of 6