Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2026-0026
Devolutions Server is affected by multiple vulnerabilities.
Affected Products
Change Log
Initial publication - 2026-07-27
Improper access control in role membership management leads to privilege escalation
7.4 High - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Improper access control in the role membership management endpoint in Devolutions Server 2026.2.12.0 and earlier allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request.
CVE(s)
CVE-2026-17568
Remediation and Workarounds
Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher.
Sensitive token exposure in NetBox synchronizer
6.3 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N
Improper access control in the NetBox synchronizer in Devolutions Server 2026.2.12.0 and earlier allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint.
CVE(s)
CVE-2026-17569
Remediation and Workarounds
Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher.
Improper access control in PAM password history endpoints
4.3 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Improper access control in the PAM password history endpoints in Devolutions Server 2026.2.12.0 and earlier allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests.
CVE(s)
CVE-2026-17570
Remediation and Workarounds
Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher.
Credits
dorjoo