Vulnerabilities (CVE)

Filtered by vendor Devolutions Subscribe
Total 168 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-3224 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 9.8 CRITICAL
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).
CVE-2026-3221 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 4.9 MEDIUM
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which allows an attacker with access to the database to obtain sensitive user information via direct database access.
CVE-2026-3204 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 9.8 CRITICAL
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.
CVE-2026-3131 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 6.5 MEDIUM
Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to access sensitive connection data.
CVE-2026-3130 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 9.8 CRITICAL
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.
CVE-2026-2590 1 Devolutions 1 Remote Desktop Manager 2026-06-17 N/A 9.8 CRITICAL
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing certain connection types while password saving is disabled.
CVE-2026-1768 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 4.3 MEDIUM
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.
CVE-2026-1007 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 7.6 HIGH
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.
CVE-2026-12162 1 Devolutions 1 Remote Desktop Manager 2026-06-17 N/A 5.5 MEDIUM
Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain.
CVE-2026-10787 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 4.3 MEDIUM
Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier
CVE-2026-10786 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 6.5 MEDIUM
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier
CVE-2026-10544 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 6.5 MEDIUM
Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier
CVE-2026-0747 1 Devolutions 1 Remote Desktop Manager 2026-06-17 N/A 3.3 LOW
Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing.
CVE-2026-0610 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
CVE-2025-8353 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 5.9 MEDIUM
UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.
CVE-2025-8312 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 7.1 HIGH
Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) : * Devolutions Server 2025.2.2.0 through 2025.2.5.0 * Devolutions Server 2025.1.12.0 and earlier
CVE-2025-6741 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 7.7 HIGH
Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.4.0 * Devolutions Server 2025.1.11.0 and earlier
CVE-2025-6523 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 7.7 HIGH
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergency codes generated by the server within a feasible timeframe. This issue affects the following versions : * Devolutions Server 2025.2.2.0 through 2025.2.3.0 * Devolutions Server 2025.1.11.0 and earlier
CVE-2025-5382 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 6.8 MEDIUM
Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.
CVE-2025-5334 1 Devolutions 1 Remote Desktop Manager 2026-06-17 N/A 7.5 HIGH
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated user to gain unauthorized access to private personal information. Under specific circumstances, entries may be unintentionally moved from user vaults to shared vaults when edited by their owners, making them accessible to other users. This issue affects the following versions : * Remote Desktop Manager Windows 2025.1.34.0 and earlier * Remote Desktop Manager macOS 2025.1.16.3 and earlier * Remote Desktop Manager Android 2025.1.3.3 and earlier * Remote Desktop Manager iOS 2025.1.6.0 and earlier