VYPR

Server

by Devolutions

CVEs (96)

  • CVE-2026-9245MedMay 22, 2026
    risk 0.33cvss 5.0epss 0.00

    Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This issue affects : * Devolutions Server 2026.1.6.0 through…

  • CVE-2026-5175MedApr 1, 2026
    risk 0.33cvss 5.0epss 0.00

    Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests.  …

  • CVE-2026-4925MedApr 1, 2026
    risk 0.33cvss 5.0epss 0.00

    Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. This issue affects Server: from…

  • CVE-2025-3768MedJun 5, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.

  • CVE-2025-0691MedJun 5, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.

  • CVE-2024-12151MedDec 4, 2024
    risk 0.33cvss 5.0epss 0.00

    Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets.

  • CVE-2023-2445MedMay 2, 2023
    risk 0.32cvss 4.9epss 0.01

    Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.

  • CVE-2026-10787MedJun 8, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server…

  • CVE-2026-9246MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions…

  • CVE-2026-9224MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * …

  • CVE-2026-9223MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

  • CVE-2026-5171MedMay 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions…

  • CVE-2026-5146MedMay 12, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions…

  • CVE-2026-8407MedMay 12, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : *…

  • CVE-2026-4989MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from…

  • CVE-2025-13765MedNov 27, 2025
    risk 0.28cvss 4.3epss 0.00

    Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

  • CVE-2025-4316MedMay 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions. This issue affects Devolutions Server versions from 2025.1.3.0 through…

  • CVE-2024-12148MedDec 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.

  • CVE-2024-10971MedNov 12, 2024
    risk 0.28cvss 4.3epss 0.01

    Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.

  • CVE-2024-3545MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining…

Page 4 of 5