CVE-2026-8407

Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.11.0 * Devolutions Server 2025.3.16.0 and earlier
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

26 May 2026, 12:32

Type Values Removed Values Added
References () https://devolutions.net/security/advisories/DEVO-2026-0010/ - () https://devolutions.net/security/advisories/DEVO-2026-0010/ - Vendor Advisory
CPE cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
First Time Devolutions devolutions Server
Devolutions

13 May 2026, 16:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

12 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 17:16

Updated : 2026-05-26 12:32


NVD link : CVE-2026-8407

Mitre link : CVE-2026-8407

CVE.ORG link : CVE-2026-8407


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-862

Missing Authorization