Devolutions
Devolutions Server: vulnerabilidades y CVE
Devolutions Server tiene 117 vulnerabilidades publicadas, 63 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE117
Últimos 12 meses63
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-93332 | Media (5.4) | 0.17% | — | 29 sept 2026 | Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API… |
| CVE-2026-93330 | Media (4.3) | 0.19% | — | 29 sept 2026 | Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset. |
| CVE-2026-100288 | Alta (7.2) | 0.07% | — | 29 sept 2026 | Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session… |
| CVE-2026-100287 | Media (5.4) | 0.17% | — | 29 sept 2026 | Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request. |
| CVE-2026-100286 | Media (6.5) | 0.22% | — | 29 sept 2026 | Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request. |
| CVE-2026-17570 | Media (4.3) | 0.25% | — | 27 jul 2026 | Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : |
| CVE-2026-17569 | Media (4.3) | 0.27% | — | 27 jul 2026 | Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue… |
| CVE-2026-17568 | Alta (8.8) | 0.42% | — | 27 jul 2026 | Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to… |
| CVE-2026-15642 | Baja (3.3) | 0.15% | — | 14 jul 2026 | Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain… |
| CVE-2026-15641 | Alta (7.1) | 0.29% | — | 14 jul 2026 | Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the… |
| CVE-2026-15637 | Alta (7.5) | 0.25% | — | 14 jul 2026 | Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or… |
| CVE-2026-15058 | Baja (3.1) | 0.21% | — | 14 jul 2026 | Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message… |
| CVE-2026-14536 | Alta (8.8) | 0.43% | — | 6 jul 2026 | Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without… |
| CVE-2026-12755 | Baja (2.7) | 0.36% | — | 25 jun 2026 | Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an… |
| CVE-2026-12117 | Media (4.3) | 0.26% | — | 16 jun 2026 | Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to which they are not authorized via a crafted… |
| CVE-2026-12105 | Media (6.5) | 0.30% | — | 16 jun 2026 | Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions. |
| CVE-2026-11890 | Media (4.3) | 0.23% | — | 16 jun 2026 | Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results. |
| CVE-2026-10787 | Media (4.3) | 0.15% | — | 8 jun 2026 | Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : |
| CVE-2026-10786 | Media (6.5) | 0.15% | — | 8 jun 2026 | Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API… |
| CVE-2026-10544 | Media (6.5) | 0.20% | — | 8 jun 2026 | Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the… |
| CVE-2026-9590 | Media (5.3) | 0.29% | — | 2 jun 2026 | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required… |
| CVE-2026-9522 | Media (5.4) | 0.23% | — | 2 jun 2026 | Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations. |
| CVE-2026-9251 | Media (5.4) | 0.24% | — | 22 may 2026 | Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain access to an entry's… |
| CVE-2026-9249 | Baja (3.1) | 0.21% | — | 22 may 2026 | Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : |
| CVE-2026-9248 | Baja (2.6) | 0.21% | — | 22 may 2026 | Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access… |
| CVE-2026-9247 | Baja (2.4) | 0.27% | — | 22 may 2026 | Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a… |
| CVE-2026-9246 | Media (4.3) | 0.25% | — | 22 may 2026 | Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a… |
| CVE-2026-9245 | Media (5) | 0.28% | — | 22 may 2026 | Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link. This… |
| CVE-2026-9224 | Media (4.3) | 0.25% | — | 22 may 2026 | Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : |
| CVE-2026-9223 | Media (4.3) | 0.25% | — | 22 may 2026 | Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.