Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2026-0014
Devolutions Server is affected by multiple vulnerabilities.
Affected Products
Change Log
Initial publication - 2026-06-02
Improper access control in edit asset permission
5.3 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.
CVE(s)
CVE-2026-9590
Remediation and Workarounds
Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later
Improper access control on account discovery scan configurations
5.4 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.
CVE(s)
CVE-2026-9522
Remediation and Workarounds
Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later
Credits
Supr4s
Improper access control in the Synchronizer feature
2.1 Low - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Improper access control in the Synchronizer feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user to use sealed credentials without triggering unseal prompts or administrator notifications via synchronizer entries.
CVE(s)
CVE-2026-10615
Remediation and Workarounds
Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later