HAUPTMENÜ

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0014

Devolutions Server is affected by multiple vulnerabilities.

Affected Products

Devolutions Server

Change Log

Initial publication - 2026-06-02

5.3 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Improper access control in edit asset permission

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.

Affected Products

CVE(s)

CVE-2026-9590

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later

5.4 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Improper access control on account discovery scan configurations

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.

Affected Products

CVE(s)

CVE-2026-9522

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later

Credits

Supr4s

2.1 Low - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Improper access control in the Synchronizer feature

Improper access control in the Synchronizer feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user to use sealed credentials without triggering unseal prompts or administrator notifications via synchronizer entries.

Affected Products

CVE(s)

CVE-2026-10615

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later