HAUPTMENÜ

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0026

Devolutions Server is affected by multiple vulnerabilities.

Affected Products

Devolutions Server
2026.2.4.0 through 2026.2.12.0
2026.1.23.0 and earlier

Change Log

Initial publication - 2026-07-27

Improper access control in role membership management leads to privilege escalation

7.4 High - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Improper access control in the role membership management endpoint in Devolutions Server 2026.2.12.0 and earlier allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request.

CVE(s)

CVE-2026-17568

Remediation and Workarounds

Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher.

Sensitive token exposure in NetBox synchronizer

6.3 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N

Improper access control in the NetBox synchronizer in Devolutions Server 2026.2.12.0 and earlier allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint.

CVE(s)

CVE-2026-17569

Remediation and Workarounds

Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher.

Improper access control in PAM password history endpoints

4.3 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Improper access control in the PAM password history endpoints in Devolutions Server 2026.2.12.0 and earlier allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests.

CVE(s)

CVE-2026-17570

Remediation and Workarounds

Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher.

Credits

dorjoo