ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2026.1 is required for this DVLS version
Sicherheit
15
CVE-2026-5171 Core - Fixed an issue where users without Activity Logs permission could still retrieve entry logs through the API
CVE-2026-7325 PAM - Fixed an LDAP coercion issue that could force DVLS to authenticate against a malicious LDAP server
CVE-2026-8477 Core - Fixed a security issue where sealed entries could be accessed through the partial sensitive-data endpoint without triggering unseal notifications
CVE-2026-9047 Core - Fixed an issue where adding an additional MFA factor could remove an existing MFA key
CVE-2026-9223 Core - Fixed a missing permission check that could allow users to create a new vault when importing an .rdx file referencing a non-existent vault
CVE-2026-9224 Core - Fixed an issue where Active Directory accounts could modify their own profile data through the API despite UI restrictions
CVE-2026-9245 Core - Fixed an open redirect vulnerability during external OAuth sign-in failures or cancellations
CVE-2026-9246 Core - Fixed an issue where handbook content and attachment metadata from sealed entries could be accessed without following the unseal workflow
CVE-2026-9247 Core - Fixed an issue where sealed credentials could be unsealed in another DVLS instance without notifying administrators, and improved handling of linked sealed credentials after import
CVE-2026-9248 Core - Fixed an issue where duplicating a connection could copy handbooks and attachments from entries the user could not access
CVE-2026-9249 Core - Fixed a password change bypass that allowed users to change passwords without providing the previous password
CVE-2026-9251 Core - Fixed an issue where non-admin users could bypass the Pending Approval flow by changing an entry's status
Core - Added audit logging for Send Copy actions so administrators can track who shared entries and with whom
Core - Hardened the authorization cache key to prevent any future cache-poisoning regression (follow-up to CVE-2026-1768)
Core - Improved authentication security to prevent external-provider sessions from bypassing password authentication under a different login method
Verbesserungen
3
Core - Improved Active Directory user creation performance
PAM - Added an option to skip TLS validation for the Windows Provider
Web - Added Command key support for multi-selection in the web interface, allowing Mac users to extend selections with Cmd-click
Fehlerbehebungen
5
Core - Fixed a NullReferenceException in the notification processing service that could leave notifications stuck in an unprocessed state
Core - Fixed an issue where Linked (External) credentials were not saved correctly on SSH entries linked to an SSH Key
Core - Fixed attachments being lost when moving an entry to another vault
Core - Fixed folder duplication so sub-entries are duplicated along with the parent folder
Web - Fixed a TypeError when opening the Advanced Search dialog as a user without a User Vault
ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2026.1 is required for this DVLS version
This version requires the .NET 10 Hosting Bundle
Sicherheit
2
CVE-2026-3204 Core - Fixed an issue where the error message page displayed a tamperable error message
CVE-2026-4434 Fix Improper certificate validation in WinRM connections
Funktionen
16
Core - Added custom vault dashboard widgets with drag-and-drop reordering
Core - Added Just-in-Time (JiT) access for SSH (sudo) sessions
Core - Added new Contractors account type with expiration date support
Core - Added support for SSH key certificates in the web
Core - Added vault priority sorting
Core - Admins can create preset dashboards for users
Core - Licenses can now be purchased directly within DVLS
Core - Multiple improvement and fixes with the synchronizer where they was mismatch with RDM
Core - Users can now request a trial directly from the application
Core - Users can now request sudo access when requesting checkout
Gateway - Added RDP credential injection for more secure session launches
Gateway - Added traffic event logs to privileged session monitoring
PAM - Added MongoDB provider support
PAM - Added PowerShell session recording
PAM - Added the ability to automatically terminate active sessions when a PAM account is checked in
PAM - Added UI to assign and manage risk levels for roles
Verbesserungen
37
Core - Added "Prompt on connection" support for linked VPN/SSH/Gateway sessions, matching the behavior already available for linked credentials
Core - Added launch links on connections for quick session sharing
Core - Added missing fields in the "Advanced" tab for SFTP connections
Core - Added OTP support for linked external vaults
Core - Added support for editing Delinea Secret Server entries directly within DVLS
Core - Admins can set the default behavior for automatically checking in PAM accounts when closing entries
Core - Deprecated read-only and restricted permission types
Core - Entra ID now enforces secret expiration with banner and email warnings
Core - Entry security settings now use inherited values by default
Core - Error reports now include connection type details
Core - Improve Entry Security Analyzer report to include all relevant fields, matching the information already available in RDM
Core - Improved license management — disabling a user now automatically removes their assigned licenses
Core - Improved performance for access requests in RDM
Core - Linked vaults can now point to entries in the same folder
Core - Public API now supports CRUD operations for folders and vaults
Core - Renamed Log Retention Policies to Database Retention Policies and added retention options for connection history, remote sessions, and traffic events
Core - Simplified license assignment in data sources
Core - Synchronizers now support scheduling by hour
Core - Tags can now be used with inheritance rules
Core - The public API now supports full CRUD operations for vaults, allowing administrators to create, read, update, and delete vaults programmatically
Core - Users can now configure multiple MFA methods at once
Gateway - Renamed "Virtual Gateway" to "Gateway ruleset"
Gateway - Sessions can now be recorded on a different gateway than the launch gateway
Gateway - The Gateway Diagnostic window now displays whether Devolutions Agent is installed and running
Gateway - The gateway list now automatically refreshes after an update request completes
PAM - Added "Create folder" option when importing PAM accounts
PAM - Added "Workspace" as a supported application option in the PAM usage policies admin section
PAM - Improved error message when no provider is specified on a PAM account
PAM - Renamed "Scan" to "Account Discovery"
PAM - Users without a PAM license can now perform basic PAM operations, such as checking out PAM credentials, without requiring a full PAM license Assignment
Web - Added a warning in the web interface when an OTP account name contains a colon (":"), consistent with existing behavior in RDM
Web - Administrators can now set permissions on entry types that are not technically supported on the web
Web - Users can now customize the "Add connection" favorites section
Web Client - Multiple UI improvements
Web Client - Updated dark theme
Fehlerbehebungen
27
Core - Fixed a regression where it was no longer possible to set a user as an administrator
Core - Fixed a scheduler timeout error that could cause scheduled tasks to fail intermittently
Core - Fixed an error occurring when too many vaults were present
Core - Fixed an error that occurred when editing account login information on a deprecated entry type
Core - Fixed an issue where exported logs from the DVLS Console were being cropped and truncated
Core - Fixed an issue where forbidden passwords could still be saved in a password list entry
Core - Fixed an issue where new Active Directory user accounts were not appearing in DVLS, preventing the auto-create on first login feature from Working correctly
Core - Fixed an issue where OAuth token rejections were incorrectly returning HTTP 200 with an empty response instead of a proper error code
Core - Fixed duplicate vault cards appearing on the dashboard
Core - Fixed notification emails being sent in English for users configured in French
Core - Fixed repeated migration attempts after SQL migration and server restart
Gateway - Fixed a issue where clicking "Close" from the session kebab menu did not always close the session on the first attempt
Gateway - Fixed a missing configuration option in the Web UI for allowing additional hosts through Devolutions Gateway
Gateway - Fixed an inconsistency in how Gateway tunnels were configured and displayed between RDM and the Web UI
Gateway - Fixed an issue where enabling vault-level security on a gateway prevented it from being used in gateway farms and PAM providers
Gateway - Fixed an issue where virtual gateways were not automatically deleted when their associated physical gateway was removed, leaving orphaned entries that no longer functioned
PAM - Fixed "Nobody" account appearing when "Ignore system users" was enabled
PAM - Fixed a security issue where non-administrator users could view other users' PAM actions in the Privileged Access logs
PAM - Fixed account discovery failure caused by circular security group membership
PAM - Fixed an error that occurred when attempting to add a folder to a newly created PAM vault during the import process
PAM - Fixed an issue where Domain Quick Scan was no longer working
PAM - Fixed an issue where groups located in the Builtin organizational unit were not visible when selecting groups for JIT (Just-In-Time) elevation
PAM - Fixed Local Windows scan failure when credentials were linked
PAM - Fixed SSH scan failure when sudo was configured with NOPASSWORD
Web - Fixed inconsistent rendering of secure notes set as Markdown across different platforms
Web - Fixed the Notification Subscriptions filter not working correctly
ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2025.3 is required for this DVLS version
Sicherheit
13
CVE-2026-5171 Core - Fixed an issue where users without Activity Logs permission could still retrieve entry logs through the API
CVE-2026-7325 PAM - Fixed an LDAP coercion issue that could force DVLS to authenticate against a malicious LDAP server
CVE-2026-8477 Core - Fixed a security issue where sealed entries could be accessed through the partial sensitive-data endpoint without triggering unseal notifications
CVE-2026-9224 Core - Fixed an issue where Active Directory accounts could modify their own profile data through the API despite UI restrictions
CVE-2026-9245 Core - Fixed an open redirect vulnerability during external OAuth sign-in failures or cancellations
CVE-2026-9246 Core - Fixed an issue where handbook content and attachment metadata from sealed entries could be accessed without following the unseal workflow
CVE-2026-9247 Core - Fixed an issue where sealed credentials could be unsealed in another DVLS instance without notifying administrators, and improved handling of linked sealed credentials after import
CVE-2026-9248 Core - Fixed an issue where duplicating a connection could copy handbooks and attachments from entries the user could not access
CVE-2026-9249 Core - Fixed a password change bypass that allowed users to change passwords without providing the previous password
CVE-2026-9251 Core - Fixed an issue where non-admin users could bypass the Pending Approval flow by changing an entry's status
Core - Added audit logging for Send Copy actions so administrators can track who shared entries and with whom
Core - Hardened the authorization cache key to prevent any future cache-poisoning regression (follow-up to CVE-2026-1768)
Core - Improved authentication security to prevent external-provider sessions from bypassing password authentication under a different login method
ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2025.3 is required for this DVLS version
Sicherheit
4
CVE-2025-13757 Core - Core - Fixed SQL injection vulnerability in the last usage logs API endpoint Privileged Sessions Monitoring
CVE-2025-13757 Core - Fixed SQL injection vulnerability in the last usage logs API endpoint
CVE-2025-13758 Core - Fixed security issue where sensitive credentials were exposed in API responses for certain connection types (SMB, HyperV, WebDav, and others)
CVE-2025-13765 Core - Fixed security issue where SMTP configuration with passwords could be viewed through the API without administrator permissions
Verbesserungen
5
Core - Added requirement for Entra ID secret expiration date during configuration to prevent unexpected login failures
Core - Improved Entra ID authentication by displaying warning banners and sending email alerts to administrators when secrets approach expiration
PAM - Added ability to create folders directly during PAM account import process
PAM - Improved PAM administrator access to automatically grant access to all PAM vaults without manual assignment
PAM - Reduced notification frequency for PAM health checks by sending alerts only once when accounts become out of sync
Fehlerbehebungen
7
Core - Fixed database permission errors for scheduler service on notification group subscriber tables
Core - Fixed database permission errors for scheduler service when inserting telemetry events
Core - Fixed duplicate key violations that occurred during server startup when users had both administrator and vault owner roles
Core - Fixed erroneous mismatch log messages during SSO authentication from RDM
Core - Fixed issue where configured additional access URIs were no longer accessible
Core - Fixed login failures and server crashes when new users attempted to authenticate
Web - Fixed issue where PAM account approval requests in the messages UI would freeze the interface and require page refresh
ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2025.3 is required for this DVLS version
Sicherheit
1
CVE-2025-11958 Core - Fixed a security vulnerability that could cause the Security Dashboard to become unavailable
Funktionen
14
Core - Added a "Linked (External Vault)" option for entries, allowing sessions to reference credentials stored in an external vault
Core - Added an onboarding experience for new installations to simplify initial setup
Core - Added an option to enable biometric lock for the Workspace app
Core - Added support for a custom, editable dictionary for passphrase generation
Core - Added the ability for users to create an API key for their account
Core - Added webhook support for specific trigger events
Core - Require re-authentication before allowing users to change MFA
Core - Users can now configure their own MFA
Gateway - Added a new setting to enable RDP reconnection
Gateway - Added network access rules for virtual gateways, with scoping by IP address, IP range, subnet, and DNS name
Gateway - Added virtual gateways, enabling different permissions on the same physical gateway
PAM - Added "Account Life Policies," consolidating PAM options and enabling inheritance at all levels (entry, folder, root)
PAM - Added conditional policies based on JIT elevation status
Web - Added support to disconnect WBEX sessions on close and when idle
Verbesserungen
14
Core - Changed default of password policy and password validation to be handled as "Inherited" - Make sure your inheritance structure is appropriate
Core - Added password expiration to password policies
Core - Added support for attachments when sending via Devo Send in DVLS
Core - Editing an entry now triggers the checkout option
Core - Improved image management with the ability to merge duplicate images
Core - Improved LDAP domain controller fallback for faster failover
Core - Improved the Entry Properties menu to align with RDM, making options easier to find
Core - Removed the ability to grant permissions on entries in vaults the user cannot access
Core - Renamed "Cleanup Log" to "Log Retention Policies"
Core - Renamed "Password Templates" to "Password Policies"
Core - Temporary access on a folder now extends to entries created in that folder after the request
PAM - Added support for editing accounts directly in RDM
PAM - Added tier detection during account discovery for domain and Entra ID accounts
PAM - Local Account scan results now exclude provider service accounts
Fehlerbehebungen
10
Core - Fixed an issue where renaming a folder with a backslash () would break the folder
Core - Fixed an issue where the password generator would not open when editing an entry
Core - Reduced the number of emails sent when Syslog is down
PAM - Fixed an error that occurred when adding JIT elevation to a PAM checkout
PAM - Fixed an error when importing computers from an AD scan
PAM - Fixed an issue where editing Account Life Policies could result in an infinite loading state
Web - Fixed an issue where SSH sessions returned "The authentication sequence has failed" when launched in the web client with a linked-to-vault private key
Web - Fixed an issue where web sessions could not be opened with a PAM credential
Web - Restored the top menu button when opening ARD web sessions
Web - Various user interface fixes and improvements
ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2025.2 is required for this DVLS version
Sicherheit
2
CVE-2025-13757 Core - Fixed SQL injection vulnerability in the last usage logs API endpoint
CVE-2025-13758 Core - Fixed security issue where sensitive credentials were exposed in API responses for certain connection types (SMB, HyperV, WebDav, and others)
Fehlerbehebungen
1
Core - Fixed erroneous mismatch log messages during SSO authentication from RDM
ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2025.1 is required for this DVLS version
Sicherheit
3
CVE-2025-4433 Core - Fixed an issue where a user with the User Management permission could promote users to admins via user groups
CVE-2025-4493 PAM - Fixed an issue where "Assigned provider privileges" in JIT privileged sets would select all available groups when adding a new provider privilege
CVE-2025-5382 Core - Fixed an issue where a user with the User Management permission could remove MFA from an admin user
Verbesserungen
1
PAM - Allowed use of the backslash character (‘') in Windows account names
Fehlerbehebungen
4
Core - Fixed an issue where sessions in the web client would not work when "Prompt on connection" was enabled
Core - Fixed an issue where the "Invalid License" error incorrectly appeared when editing a user
Core - Fixed an issue where users could lose all repository access, causing a red "X" to appear on vault selection in RDM
PAM - Prevented multiple emails from being sent when an account fails to reset its password on schedule
ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2024.3 is required for this DVLS version
Sicherheit
2
CVE-2025-4316 PAM - Fixed an issue where an admin could approve their own checkout even if approval was required
PAM - Fixed an issue where "Assigned provider privileges" in JIT privileged sets would select all available groups when adding a new provider privilege
ErforderlichIf you are using a client (RDM, PowerShell, etc.), version 2024.3 is required for this DVLS version
Sicherheit
1
CVE-2025-2003 PAM - Fixed an issue where the "Add in Root" permission was not respected in PAM vaults
Wichtige Änderungen
1
Core - We've updated our integration with your Entra ID environment to align with Microsoft Entra's latest security policies. As part of this update, client secrets with an expiration period longer than two years are now deprecated. Please review and update your current configuration by following the instructions in the following link: https://docs.devolutions.net/server/kb/how-to-articles/azure-portal-configuration-guide-microsoft-authentication
Fehlerbehebungen
2
Core - Fixed an error that could occur when exporting login history
Core - Fixed an issue where the folder structure could disappear when adding or editing entries/folders in RDM
ErforderlichDatenbank-Upgrade erforderlichRDM and Devolutions Server Console 2022.2 are required to use this version
Wichtige Änderungen
3
Core - .NET 6.0 is now required
Gateway - Devolutions Gateway now requires a license (unlicensed usage will be refused except for side-by-side installation that can have up to 5 concurrent sessions without a license)
Core - Website entry (previously "Web Browser (HTTP/HTTPS)") now has Workspace browser extension enabled by default
Funktionen
10
Core - Emergency access to allow an access even if providers are down (Azure or AD)
Core - New permission : "Delete Documentation"
Core - New permission : "View Sensitive"
Core - Notifications : Users can be notified on actions made on entries
Core - Security policies available to allow/deny users with different conditions
Core - Security policies available to force/skip 2FA with different conditions
Gateway - Support for new protocols : VNC, ARD, SCP, SFTP, PowerShell (WinRM, SSH), Embedded Websites
PAM - Add link with ticketing system (JIRA) to list tickets during the checkout operation
PAM - Support for password reset for MySQL users, Oracle users and Cisco users
PAM - Support for standalone privileged accounts
Verbesserungen
14
Core - Added "append to the username" and "prepend to the username" modes for OTP usage
Core - Added a button to test ticketing system configuration
Core - Added more fields in asset dashboard (UPN, custom fields)
Core - Added a new license for the PAM Module (the license is included for those already using the PAM module with a DVLS license bought before September 30th 2021)
PAM - Added local Windows account management
Web - Added an option to regenerate Devolutions Gateway key pair on demand
Web - Added batch edit to grant permissions all at once on an entry
Fehlerbehebungen
5
Core - Fixed an issue where a user can delete entries without permission
Core - Fixed the display of shortcut entries
Core - Stack overflow error when migrating the domain user groups with their SID
PAM - Fixed an issue where approval workflow didn't work when approved by an "approver"
Core - The user vault has now the same features as a standard vault (i.e.: attachments, history, documentation)
Introduced a distinction between sensitive properties and passwords in Information Entries. The view password permissions now only affect passwords specifically
Funktionen
10
Core - Added support for Devolutions Gateway (Jet)
Core - Added the "Last login" report
Core - Added the entry type: azure service principal
Core - Added the field Tenant ID on API Key
PAM - Added a system of policies on team folders for easier management
PAM - Added the delta between results when scanning a domain
Web - Added support for default icon color
Web - Added the option when enter a licence or request a trial when the license is expired or when there is no license
Web - The interface is available in read-only when the license is expired or when there is no license
Web - The scheduled reports now support more reports
Verbesserungen
27
Core - Added a timeout setting to Radius configuration
Core - Added Devolutions Authentificator as a supported 2FA
Core - Added handling of the custom controls on web entries for DWL
Core - Added the authentication method on the login history report
Core - Added the expression "is not" when setting a filter on a subscription
Core - SqlException when starting a connection from a templage
Core - Syslog events, only sends the title of the stack trace
Core - Updated the library for sending emails
Web - Added a download button on document's dashboard
Web - Added a message when the license is expired
Web - Added custom fields on web entries
Web - Added multiple gateways on SCP and SFTP entries
Web - Added multiple gateways on SSH Shel, SSH Tunnel and SSH Port Forward entries
Web - Added Recents, on the new entry dialog
Web - Added recovery codes for OTPs
Web - Added the "Disconnect Data Source" option in the administration section
Web - Added the OPT on Web entries
Web - Added the option to set the "Allow Offline" to a vault
Web - Added the options to view and download the Private key
Web - changed UI
Web - Manage the password setting "Force Default Template"
Web - Remove the email being mandatory when creating a user
Web - secure message, Added the options to "Delete All" and "Mark all as read"
Web - Update the default date range to "today" instead of "Last 7 days" on the activity log report
Web - Updated Radius login labels
Web - Updated the icons
Web - Updated the scrolling when navigating to an entry from the search
Fehlerbehebungen
43
Core - Access was denied on api call for the documentaion
Core - Error SecurityTokenExpiredException received several time a day
Core - Error when adding an email to a user that didn't already had one
Core - Error when enabling the Windows Event Log
Core - Error when importing in the Private Vault
Core - Error with RDM on limited mode
Core - Fix access denied error on documentation
Core - Fix CORS
Core - Fix templates showing in the activity logs
Core - MaxMind GeoIP block everything
Core - Sql Injection
Core - Updated date format on reports
Core - Updated the default STMP Port
Core - Updated the SQL Queries when doing cleanup tasks to avoid timeouts
Core - Wrong log in "Connected User" report when connected from the Launcher
RDM - Cannot download Session recording form Recording Server in RDM
Web - "Prompt for comment" memo is overflow window is not tall enough
Web - Bad email format result in JSON error when editing a user
Web - Checkout UI issue on Firefox
Web - Error when trying to upload an SSH key
Web - Fix cannot assign users and user groups when creation a vault
Web - Fix error on reports when no vault is selected
Web - Fix loading the domain user speed issue
Web - Fix secure message color in dark mode
Web - Fix should not be able to set status on an entry when a check out is required
Web - Fix the vault menu item being available when there are no vault
Web - Fix variable not resolved on connections
Web - Fix variable not resolved on sub-connections
Web - Infinite loading when Azure token expires
Web - Missing icons on the web interface
Web - notification subscriber edit window is not tall enough
Web - On the Login History reports is not showing all entries
Web - RDP Template doesn't save "local ressources"
Web - Tab title is not updated
Web - The licence count is not updated when managing licenses
Web - The password reset is not applied when switching users
Web - The recurrence is not shown properly on the scheduled report calendar
Web - The website does not load properly when the the database is not reachable
Web - UI issue in Vault on Firefox
Web - UI issue when adding a user
Web - Unable to create a Contact Company entry in a folder
Web - User loses its license when changing the user type