cbcvebase.

Devolutions Server vulnerabilities

104 known vulnerabilities affecting devolutions/devolutions_server.

Total CVEs
104
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH26MEDIUM60LOW9UNKNOWN3

Vulnerabilities

Page 1 of 6
CVE-2026-3224P2CRITICALCVSS 9.8fixed in 2025.3.16.02026-03-03
CVE-2026-3224 [CRITICAL] CWE-287 CVE-2026-3224: Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).
nvd
CVE-2026-0610P2CRITICALCVSS 9.8≥ 2025.3.1.0, < 2025.3.14.02026-01-19
CVE-2026-0610 [CRITICAL] CWE-89 CVE-2026-0610: SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
nvd
CVE-2025-12485P3HIGHCVSS 8.8fixed in 2025.2.17.0≥ 2025.3.2.0, < 2025.3.6.02025-11-06
CVE-2025-12485 [HIGH] CWE-269 CVE-2025-12485: Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-priv Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through 2025.3.5.0 *
nvd
CVE-2025-13757P3HIGHCVSS 8.8fixed in 2025.2.21.0≥ 2025.3.2.0, < 2025.3.10.02025-11-27
CVE-2025-13757 [HIGH] CWE-89 CVE-2025-13757: SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.
nvd
CVE-2026-4924P3HIGHCVSS 8.2fixed in 2025.3.18.0≥ 2026.1.1.0, < 2026.1.12.02026-04-01
CVE-2026-4924 [HIGH] CWE-1390 CVE-2026-4924: Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026. Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially authenticated session token.
nvd
CVE-2026-4828P3HIGHCVSS 8.2fixed in 2025.3.18.0≥ 2026.1.1.0, < 2026.1.12.02026-04-01
CVE-2026-4828 [HIGH] CWE-1390 CVE-2026-4828: Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request.
nvd
CVE-2026-3130P3CRITICALCVSS 9.8fixed in 2025.3.16.02026-03-03
CVE-2026-3130 [CRITICAL] CWE-841 CVE-2026-3130: Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an au Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.
nvd
CVE-2024-2915P3HIGHCVSS 8.8fixed in 2024.1.8.02024-03-26
CVE-2024-2915 [HIGH] CWE-863 CVE-2024-2915: Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an at Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.
nvd
CVE-2025-11957P3HIGHCVSS 8.4fixed in 2025.2.14.02025-10-22
CVE-2025-11957 [HIGH] CWE-639 CVE-2025-11957: Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlie Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.
nvd
CVE-2025-4433P3HIGHCVSS 8.8fixed in 2025.1.9.02025-05-30
CVE-2025-4433 [HIGH] CWE-284 CVE-2025-4433: Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Management" and "User Group Management" permissions to perform privilege escalation by adding users to groups with administrative privileges.
nvd
CVE-2025-6523P3HIGHCVSS 7.7≤ 2025.1.11.0≥ 2025.2.2.0, < 2025.2.4.02025-07-22
CVE-2025-6523 [HIGH] CWE-1391 CVE-2025-6523: Use of weak credentials in emergency authentication component in Devolutions Server allows an unauth Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Se
nvd
CVE-2024-2921P3CRITICALCVSS 9.8fixed in 2024.1.8.02024-03-26
CVE-2024-2921 [CRITICAL] CWE-306 CVE-2024-2921: Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allow Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.
nvd
CVE-2026-3204P3CRITICALCVSS 9.8≤ 2025.3.16.02026-03-03
CVE-2026-3204 [CRITICAL] CWE-20 CVE-2026-3204: Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier all Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.
nvd
CVE-2023-0951P3HIGHCVSS 8.8≤ 2022.3.122023-03-01
CVE-2023-0951 [HIGH] CVE-2023-0951: Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could al Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perform privileged actions.
nvd
CVE-2023-0953P3HIGHCVSS 8.8≤ 2022.3.122023-03-01
CVE-2023-0953 [HIGH] CWE-89 CVE-2023-0953: Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and ear Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
nvd
CVE-2021-23921P3CRITICALCVSS 9.1fixed in 2020.32021-04-01
CVE-2021-23921 [CRITICAL] CVE-2021-23921: An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Passw An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.
nvd
CVE-2025-2280P3HIGHCVSS 8.1fixed in 2024.3.6.02025-03-13
CVE-2025-2280 [HIGH] CWE-284 CVE-2025-2280: Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature.
nvd
CVE-2025-2277P3HIGHCVSS 7.5fixed in 2025.1.3.02025-03-13
CVE-2025-2277 [HIGH] CWE-200 CVE-2025-2277: Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and e Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.
nvd
CVE-2022-33996P3HIGHCVSS 8.8fixed in 2022.2.02022-07-07
CVE-2022-33996 [HIGH] CWE-276 CVE-2022-33996: Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexis Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
nvd
CVE-2026-9047P3HIGHCVSS 7.6≥ 2026.1.6.0, < 2026.1.19.02026-05-22
CVE-2026-9047 [HIGH] CWE-305 CVE-2026-9047: Improper handling of factor key state in the multi-factor authentication management feature in Devol Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0
nvd
Devolutions Server vulnerabilities | cvebase