By vendor

Devolutions vulnerabilities

Known CVEs affecting Devolutions products, prioritized by severity, with SEC.co remediation and detection guidance.

15 published vulnerabilities

  • CVE-2026-12161HIGH 8.8

    A vulnerability in Devolutions Remote Desktop Manager's SSH Elevate Shell feature allows authenticated users to bypass input validation and execute arbitrary commands on remote SSH hosts. An attacker with permission to create or modify shared SSH entries can craft a malicious alternate username that, when combined with user interaction to trigger the Elevate Shell action, will execute unauthorized commands using the stored elevation credentials. This is a post-authentication attack that leverages credential misuse within the application's own features.

  • CVE-2026-14536HIGH 8.8

    Devolutions Server 2026.2.9.0 contains a flaw that allows attackers with valid login credentials to skip multi-factor authentication (MFA) and gain full access to the system. The vulnerability occurs when the server encounters an invalid default MFA configuration, creating a gap in the authentication enforcement mechanism. An attacker who has already compromised a user's password can exploit this to bypass the MFA requirement entirely, gaining the same level of access as if they had completed the second factor.

  • CVE-2026-10696HIGH 7.5

    Devolutions UniGetUI, a package manager frontend, contains a flaw in how it matches installed applications to available updates. An attacker who contributes a malicious package to the WinGet community catalog can craft a package with a name that partially matches an existing installed application. When a user attempts to apply updates, UniGetUI may incorrectly associate the legitimate application with the attacker's malicious package and execute the attacker's installer instead. This affects version 2026.2.0 and earlier.

  • CVE-2026-13372HIGH 7.2

    A flaw in Devolutions Remote Desktop Manager's PowerShell VPN editor allows an authenticated attacker to execute PowerShell scripts in another user's security context. The vulnerability exists in versions 2026.2.5 through 2026.2.11 and exploits how the application resolves VPN script links by display name. An attacker with write access to a shared workspace can create a specially named malicious VPN script that collides with an existing legitimate script link, causing the victim to unknowingly run the attacker's code with their privileges. This requires both authentication and workspace write access, limiting the attack surface but creating a serious privilege elevation risk within collaborative environments.

  • CVE-2026-10544MEDIUM 6.5

    Devolutions Server contains a vulnerability in its built-in PAM (Privileged Access Management) provider that allows authenticated users with vault write access to inject commands into password rotation templates. When those templates execute, the injected commands run on systems managed by the PAM provider, potentially granting attackers control over critical infrastructure. The issue stems from insufficient sanitization of special characters and command syntax in template processing.

  • CVE-2026-10786MEDIUM 6.5

    A flaw in Devolutions Server's ticketing integration settings allows authenticated users with low-level permissions to retrieve cleartext credentials for third-party ticketing systems through a specially crafted API request. An attacker with basic user access could exploit this to obtain sensitive integration credentials without proper authorization checks, potentially enabling lateral movement or unauthorized access to connected ticketing platforms.

  • CVE-2026-12105MEDIUM 6.5

    Devolutions Server contains an access control weakness that allows authenticated users to view attachments they shouldn't have permission to access. The issue occurs when a folder is duplicated—the inherited permissions aren't properly restricted, giving users unintended access to sensitive files. An attacker would need valid login credentials to exploit this, but once authenticated, they could escalate their view into restricted attachment areas without additional authorization.

  • CVE-2026-13437MEDIUM 6.5

    Devolutions PowerShell Universal version 2026.2.0 contains a vulnerability where authentication tokens (App Tokens) are exposed in plaintext within job API responses. An authenticated user with permission to read AI Agent jobs can capture these tokens and reuse them to gain unauthorized access to protected resources, potentially with higher privileges than their own account. This affects any organization using the vulnerable version where job APIs are accessible to users with lower privilege levels.

  • CVE-2026-12162MEDIUM 5.5

    Devolutions Remote Desktop Manager version 2026.2.8 contains a flaw in how it validates the identity of social login providers during the autofill process. An attacker can craft a malicious web entry pointing to a lookalike domain that mimics a legitimate social login provider. When a user interacts with this entry, the application fails to properly verify the provider's authenticity, potentially exposing stored social login credentials to the attacker. This is a social engineering vulnerability that exploits the trust users place in the autofill mechanism.

  • CVE-2026-9522MEDIUM 5.4

    Devolutions Server versions 2026.1.19 and earlier contain an access control weakness in the PAM (Privileged Access Management) account discovery feature. An authenticated user without admin rights can delete network discovery scan configurations that they shouldn't be able to modify. This means non-privileged users can disrupt the organization's ability to discover and inventory network accounts, potentially hindering PAM operations and compliance visibility.

  • CVE-2026-9590MEDIUM 5.3

    Devolutions Server versions up to and including 2026.1.19 contain an access control weakness that allows authenticated users with permission to edit entries to modify asset information beyond their intended scope. An attacker with entry edit privileges can bypass the permission validation checks and alter assets they shouldn't be able to access, potentially compromising the integrity of credential and asset data within the server.

  • CVE-2026-10787MEDIUM 4.3

    Devolutions Server contains a flaw in its API for managing deleted user groups that fails to properly check permissions. An authenticated user with low-level access can craft specific API requests to view metadata about deleted user groups they should not be able to see. The vulnerability requires an attacker to already have valid credentials, limiting the attack surface, but it does represent a breach of data compartmentalization within the system.

  • CVE-2026-11890MEDIUM 4.3

    Devolutions Server versions 2026.2.5 and 2026.1.21 contain an access control flaw that allows any authenticated user to view account discovery scan results they should not have permission to access. An attacker with valid credentials to the server can retrieve sensitive account information gathered during automated discovery scans, potentially exposing credentials or account details that should be restricted to authorized administrators.

  • CVE-2026-12117MEDIUM 4.3

    Devolutions Server 2026.2.5 contains an access control flaw that allows authenticated users to view metadata about social login configurations they shouldn't have permission to access. An attacker with a valid vault membership can craft specific API requests to enumerate social login entry details, potentially revealing sensitive integration information. This is a low-risk exposure of metadata rather than a direct compromise mechanism, but it can aid reconnaissance or inform follow-up attacks against connected identity systems.

  • CVE-2026-12755LOW 2.7

    Devolutions Server contains a flaw in how it validates user input on Active Directory discovery endpoints used for PAM (Privileged Access Management) functions. An authenticated user with UserGroupsView permission can manipulate the DomainName parameter to trick the server into attempting authentication to a system they control, thereby capturing NTLMv2 credential hashes from the PAM provider. This is a credential exposure risk limited to authenticated users with specific permissions.