Devolutions

Devolutions Server

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 16.06.2026 18:25:19
  • Zuletzt bearbeitet 16.06.2026 20:41:35

Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to which they are not authorized via a crafted API request.

  • EPSS 0.23%
  • Veröffentlicht 16.06.2026 18:24:00
  • Zuletzt bearbeitet 16.06.2026 20:41:35

Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results.

  • EPSS 0.2%
  • Veröffentlicht 08.06.2026 18:26:45
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected ...

  • EPSS 0.16%
  • Veröffentlicht 08.06.2026 18:26:25
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 ...

  • EPSS 0.15%
  • Veröffentlicht 08.06.2026 18:26:09
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : ...

  • EPSS 0.14%
  • Veröffentlicht 02.06.2026 14:08:07
  • Zuletzt bearbeitet 22.07.2026 19:10:00

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.

  • EPSS 0.18%
  • Veröffentlicht 02.06.2026 14:07:08
  • Zuletzt bearbeitet 22.07.2026 19:10:00

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.

  • EPSS 0.25%
  • Veröffentlicht 22.05.2026 15:30:08
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an at...

  • EPSS 0.19%
  • Veröffentlicht 22.05.2026 15:29:25
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain access to an entry's data via a crafted status change...

  • EPSS 0.23%
  • Veröffentlicht 22.05.2026 15:28:47
  • Zuletzt bearbeitet 23.07.2026 16:10:00

Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue aff...