Server
by Devolutions
CVEs (114)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-13683 | Med | 0.42 | 6.5 | 0.00 | Nov 28, 2025 | Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0. | ||
| CVE-2025-12808 | Med | 0.42 | 6.5 | 0.00 | Nov 6, 2025 | Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through… | ||
| CVE-2025-4493 | Med | 0.42 | 6.5 | 0.00 | May 28, 2025 | Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions : * Devolutions Server 2025.1.3.0 through… | ||
| CVE-2025-2278 | Med | 0.42 | 6.5 | 0.00 | Mar 13, 2025 | Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID. | ||
| CVE-2024-12196 | Med | 0.42 | 6.5 | 0.00 | Dec 4, 2024 | Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission. | ||
| CVE-2024-6512 | Med | 0.42 | 6.5 | 0.00 | Sep 25, 2024 | Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism. | ||
| CVE-2024-5072 | Med | 0.42 | 6.5 | 0.01 | May 17, 2024 | Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request. | ||
| CVE-2023-6588 | Med | 0.42 | 6.5 | 0.01 | Dec 7, 2023 | Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline. | ||
| CVE-2023-5575 | Med | 0.42 | 6.5 | 0.01 | Oct 16, 2023 | Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent. | ||
| CVE-2023-1603 | Med | 0.42 | 6.5 | 0.01 | Apr 2, 2023 | Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision. | ||
| CVE-2023-1201 | Med | 0.42 | 6.5 | 0.01 | Mar 10, 2023 | Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains. | ||
| CVE-2023-0952 | Med | 0.42 | 6.5 | 0.01 | Mar 1, 2023 | Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization. | ||
| CVE-2023-0661 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2023 | Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data. | ||
| CVE-2022-3781 | Med | 0.42 | 6.5 | 0.00 | Nov 1, 2022 | Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This… | ||
| CVE-2021-28048 | Med | 0.42 | 6.5 | 0.01 | Apr 14, 2021 | An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page. | ||
| CVE-2025-3517 | Med | 0.41 | 6.3 | 0.00 | May 1, 2025 | Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username. | ||
| CVE-2024-4846 | Med | 0.41 | 6.3 | 0.00 | Jun 25, 2024 | Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab. | ||
| CVE-2021-23925 | Med | 0.40 | 6.1 | 0.01 | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document. | ||
| CVE-2026-3638 | Med | 0.38 | 5.9 | 0.00 | Mar 9, 2026 | Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated user to restore deleted users and roles via crafted API requests. | ||
| CVE-2025-8353 | Med | 0.38 | 5.9 | 0.00 | Jul 30, 2025 | UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request… |
- risk 0.42cvss 6.5epss 0.00
Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8.0; Remote Desktop Manager: through 2025.3.23.0.
- risk 0.42cvss 6.5epss 0.00
Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through…
- risk 0.42cvss 6.5epss 0.00
Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions : * Devolutions Server 2025.1.3.0 through…
- risk 0.42cvss 6.5epss 0.00
Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID.
- risk 0.42cvss 6.5epss 0.00
Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.
- risk 0.42cvss 6.5epss 0.00
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.
- risk 0.42cvss 6.5epss 0.01
Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.
- risk 0.42cvss 6.5epss 0.01
Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier. This allows an attacker with access to the Workspace application to access credentials when offline.
- risk 0.42cvss 6.5epss 0.01
Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.
- risk 0.42cvss 6.5epss 0.01
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.
- risk 0.42cvss 6.5epss 0.01
Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
- risk 0.42cvss 6.5epss 0.01
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
- risk 0.42cvss 6.5epss 0.01
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
- risk 0.42cvss 6.5epss 0.00
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This…
- risk 0.42cvss 6.5epss 0.01
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
- risk 0.41cvss 6.3epss 0.00
Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.
- risk 0.41cvss 6.3epss 0.00
Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.
- risk 0.38cvss 5.9epss 0.00
Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated user to restore deleted users and roles via crafted API requests.
- risk 0.38cvss 5.9epss 0.00
UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request…
Page 3 of 6