« Volver al listado

CVE-2026-9248

Estado: AnalizadaBaja (2.6)—

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request.

This issue affects :

Detalles técnicos trazas, registros y código del informe original
  *  Devolutions Server 2026.1.6.0 through 2026.1.16.0
  *  Devolutions Server 2025.3.20.0 and earlier

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-9248",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-9248",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-22T16:56:40.752057Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.6,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@devolutions.net",
      "affectedData": [
        {
          "vendor": "Devolutions",
          "product": "Server",
          "versions": [
            {
              "status": "affected",
              "version": "2026.1.6.0",
              "versionType": "custom",
              "lessThanOrEqual": "2026.1.16.0"
            },
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2025.3.20.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-22T16:16:25.860",
  "references": [
    {
      "url": "https://devolutions.net/security/advisories/DEVO-2026-0013/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@devolutions.net"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@devolutions.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request.\n\nThis issue affects :\n\n  *  Devolutions Server 2026.1.6.0 through 2026.1.16.0\n  *  Devolutions Server 2025.3.20.0 and earlier"
    },
    {
      "lang": "es",
      "value": "Omisión de autorización en la función de duplicación de entradas en Devolutions Server permite a un usuario autenticado con acceso de escritura a cualquier bóveda copiar documentación y archivos adjuntos de una entrada en una bóveda a la que no pueden acceder mediante una solicitud de guardado manipulada.\n\nEste problema afecta a:\n\n  *  Devolutions Server 2026.1.6.0 hasta 2026.1.16.0\n  *  Devolutions Server 2025.3.20.0 y versiones anteriores"
    }
  ],
  "lastModified": "2026-07-23T16:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E689234-ABCB-49B5-AD17-00C2E2FC3B11",
              "versionEndExcluding": "2025.3.22.0"
            },
            {
              "criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02811CA7-5B80-47D7-B826-18B3CB1213E9",
              "versionEndExcluding": "2026.1.19.0",
              "versionStartIncluding": "2026.1.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@devolutions.net"
}