MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0014

Devolutions Server is affected by multiple vulnerabilities.

Affected Products

Devolutions Server

Change Log

Initial publication - 2026-06-02

Improper access control in edit asset permission

5.3 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.

CVE(s)

CVE-2026-9590

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later

Improper access control on account discovery scan configurations

5.4 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.

CVE(s)

CVE-2026-9522

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later

Credits

Supr4s

Improper access control in the Synchronizer feature

2.1 Low - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Improper access control in the Synchronizer feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user to use sealed credentials without triggering unseal prompts or administrator notifications via synchronizer entries.

CVE(s)

CVE-2026-10615

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later