cbcvebase.

Devolutions Server vulnerabilities

78 known vulnerabilities affecting devolutions/server.

Total CVEs
78
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH19MEDIUM46LOW8

Vulnerabilities

Page 1 of 4
CVE-2026-3224P2CRITICALCVSS 9.8≤ 2025.3.15.02026-03-03
CVE-2026-3224 [CRITICAL] CWE-287 CVE-2026-3224: Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).
nvd
CVE-2026-0610P2CRITICALCVSS 9.8≥ 2025.3.1, ≤ 2025.3.122026-01-19
CVE-2026-0610 [CRITICAL] CWE-89 CVE-2026-0610: SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
nvd
CVE-2025-12485P3HIGHCVSS 8.8≥ 2025.3.2.0, ≤ 2025.3.5.0≤ 2025.2.15.02025-11-06
CVE-2025-12485 [HIGH] CWE-269 CVE-2025-12485: Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-priv Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through 2025.3.5.0 *
nvd
CVE-2025-13757P3HIGHCVSS 8.8≤ 2025.2.202025-11-27
CVE-2025-13757 [HIGH] CWE-89 CVE-2025-13757: SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.
nvd
CVE-2026-4924P3HIGHCVSS 8.2≤ 2026.1.112026-04-01
CVE-2026-4924 [HIGH] CWE-1390 CVE-2026-4924: Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026. Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially authenticated session token.
nvd
CVE-2026-4828P3HIGHCVSS 8.2≤ 2026.1.112026-04-01
CVE-2026-4828 [HIGH] CWE-1390 CVE-2026-4828: Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request.
nvd
CVE-2026-3130P3CRITICALCVSS 9.8fixed in 2025.3.162026-03-03
CVE-2026-3130 [CRITICAL] CWE-841 CVE-2026-3130: Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an au Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.
nvd
CVE-2024-2915P3HIGHCVSS 8.8≤ 2024.1.62024-03-26
CVE-2024-2915 [HIGH] CWE-863 CVE-2024-2915: Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an at Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.
nvd
CVE-2025-11957P3HIGHCVSS 8.4≤ 2025.2.12.02025-10-22
CVE-2025-11957 [HIGH] CWE-639 CVE-2025-11957: Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlie Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.
nvd
CVE-2025-4433P3HIGHCVSS 8.8≤ 2025.1.7.02025-05-30
CVE-2025-4433 [HIGH] CWE-284 CVE-2025-4433: Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Management" and "User Group Management" permissions to perform privilege escalation by adding users to groups with administrative privileges.
nvd
CVE-2025-6523P3HIGHCVSS 7.7≤ 2025.1.11.0≥ 2025.2.2.0, ≤ 2025.2.3.02025-07-22
CVE-2025-6523 [HIGH] CWE-1391 CVE-2025-6523: Use of weak credentials in emergency authentication component in Devolutions Server allows an unauth Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Se
nvd
CVE-2024-2921P3CRITICALCVSS 9.8≤ 2024.1.62024-03-26
CVE-2024-2921 [CRITICAL] CWE-306 CVE-2024-2921: Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allow Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.
nvd
CVE-2026-3204P3CRITICALCVSS 9.8≤ 2025.3.162026-03-03
CVE-2026-3204 [CRITICAL] CWE-20 CVE-2026-3204: Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier all Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.
nvd
CVE-2025-2280P3HIGHCVSS 8.1≤ 2024.3.4.02025-03-13
CVE-2025-2280 [HIGH] CWE-284 CVE-2025-2280: Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature.
nvd
CVE-2025-2277P3HIGHCVSS 7.5≤ 2024.3.13.02025-03-13
CVE-2025-2277 [HIGH] CWE-200 CVE-2025-2277: Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and e Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.
nvd
CVE-2026-9047P3HIGHCVSS 7.6≥ 2026.1.6.0, ≤ 2026.1.16.02026-05-22
CVE-2026-9047 [HIGH] CWE-305 CVE-2026-9047: Improper handling of factor key state in the multi-factor authentication management feature in Devol Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0
cvelistv5nvd
CVE-2025-6741P3HIGHCVSS 7.7≤ 2025.1.11.0≥ 2025.2.2.0, ≤ 2025.2.4.02025-07-22
CVE-2025-6741 [HIGH] CWE-284 CVE-2025-6741: Improper access control in secure message component in Devolutions Server allows an authenticated us Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.4.0 * Devolutions Server 2025.1.11.0 and earlier
nvd
CVE-2024-1764P3HIGHCVSS 7.6≤ 2023.3.14.02024-03-05
CVE-2024-1764 [HIGH] CWE-269 CVE-2024-1764: Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14 Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after the expiration under specific circumstances
nvd
CVE-2023-5240P3HIGHCVSS 7.5≤ 2023.2.8.02023-10-13
CVE-2023-5240 [HIGH] CWE-284 CVE-2023-5240: Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allow Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
nvd
CVE-2026-4434P3HIGHCVSS 8.1fixed in 2026.12026-03-20
CVE-2026-4434 [HIGH] CWE-295 CVE-2026-4434: Improper certificate validation in the PAM propagation WinRM connections allows a network attacker Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.
nvd
Devolutions Server vulnerabilities | cvebase