MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0017

Devolutions Server is affected by multiple vulnerabilities.

Affected Products

Devolutions Server
2026.2.5 and earlier
Devolutions Server
2026.1.21 and earlier

Change Log

Initial publication - 2026-06-16

5.3 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Improper access control in PAM account discovery results

Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results.

Affected Products

CVE(s)

CVE-2026-11890

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.7, 2026.1.22

5.3 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Improper access control on social login connection endpoint

Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to which they are not authorized via a crafted API request.

Affected Products

CVE(s)

CVE-2026-12117

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.7

6 Medium - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Improper access control on folder duplication

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.

Affected Products

CVE(s)

CVE-2026-12105

Remediation and Workarounds

Upgrade to Devolutions Server 2026.2.7 or higher, 2026.1.22 or higher