CVE-2026-12105: Devolutions Server Improper Access Control Allows Unauthorized Attachment Disclosure
Devolutions Server contains an access control weakness that allows authenticated users to view attachments they shouldn't have permission to access. The issue occurs when a folder is duplicated—the inherited permissions aren't properly restricted, giving users unintended access to sensitive files. An attacker would need valid login credentials to exploit this, but once authenticated, they could escalate their view into restricted attachment areas without additional authorization.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-862
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-16 / 2026-06-18
NVD description (verbatim)
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12105 is classified as an improper access control vulnerability (CWE-862) affecting Devolutions Server versions 2026.2.5 and 2026.1.21. The flaw stems from insufficient permission validation during folder duplication operations. When a folder is cloned, inherited permissions are applied without properly restricting access to attachments within that folder structure. An authenticated user can navigate the duplication feature to gain unintended visibility into confidential attachments. The CVSS 3.1 score of 6.5 (MEDIUM) reflects the requirement for valid authentication and the confidentiality impact, with no integrity or availability compromise.
Business impact
This vulnerability creates a compliance and data governance risk for organizations using Devolutions Server as a secrets and credential management platform. Employees or contractors with basic authentication access could uncover sensitive attachments—potentially including passwords, API keys, certificates, or documentation—that should remain restricted by role or department. In regulated environments (finance, healthcare, government), this unauthorized disclosure could trigger audit findings and data breach notifications depending on the content and scope of exposure. The impact is primarily confidentiality-driven rather than destructive, but the damage extends to trust and operational security assumptions.
Affected systems
Devolutions Server versions 2026.2.5 and 2026.1.21 are confirmed vulnerable. Organizations running these specific releases should prioritize assessment. Verify your deployment version in Devolutions Server's admin console or via the Help > About menu. Versions outside this range have not been confirmed affected by this particular flaw, but check Devolutions' official advisory for a complete patch timeline and whether earlier or later versions require updates.
Exploitability
Exploitation requires valid Devolutions Server credentials—no unauthenticated attack path exists. The technical barrier is low: an attacker leverages the standard folder duplication feature available in the UI, making it easily discoverable during normal system exploration. There is no known public exploit code, and the issue is not listed on the CISA KEV (Known Exploited Vulnerabilities) catalog, suggesting limited wild exploitation as of the publication date. However, the simplicity of the attack vector means insider threat or compromised account scenarios are realistic.
Remediation
Devolutions has released patched versions addressing this access control defect. Organizations should update Devolutions Server to a version newer than 2026.2.5 and 2026.1.21 as soon as practical. Consult the official Devolutions security advisory or release notes to confirm the specific patched version for your deployment track. Interim mitigations—such as restricting folder duplication permissions to administrators only—may reduce risk, but are not a substitute for patching.
Patch guidance
Contact Devolutions support or review the official security advisory at Devolutions' website for the exact patched version numbers and release dates. Plan a maintenance window to update Devolutions Server, ensuring you back up your configuration and database beforehand. Test the patch in a non-production environment first to confirm no integration issues with connected clients or workflows. After patching, conduct a post-update audit to verify folder permission inheritance is properly enforced.
Detection guidance
Monitor Devolutions Server audit logs for unusual folder duplication activity, especially by users who do not normally perform administrative operations. Look for patterns of rapid folder cloning followed by attachment access from accounts with limited expected permissions. Review access control policies and test permission inheritance manually: duplicate a restricted folder and verify that inherited permissions are genuinely limiting access as intended. Network-based detection is limited since this is an authorization flaw within the application; focus on server-side event logging and periodic permission audits.
Why prioritize this
Although the CVSS score is MEDIUM (6.5), the priority should be elevated above raw score alone because Devolutions Server is a sensitive asset—it holds passwords, secrets, and credentials for critical infrastructure. Unauthorized attachment disclosure within such a system is particularly damaging to operational security posture. The simplicity of exploitation (folder duplication via standard UI) and the insider/compromised-account threat vectors make this a practical risk. Organizations should treat this as HIGH priority for patching, particularly if they have evidence of unusual duplication activity or strict data governance requirements.
Risk score, explained
The CVSS 3.1 score of 6.5 reflects a network-accessible vulnerability requiring low attack complexity and valid authentication (PR:L), resulting in high confidentiality impact (C:H) but no integrity or availability loss (I:N, A:N). The score appropriately captures the access control flaw's severity. However, context matters: Devolutions Server's role as a privileged credential store elevates business risk beyond the numerical score, and insider/compromised-credential scenarios are more probable than typical enterprise vulnerabilities. Use the 6.5 score as a baseline, not a ceiling, for remediation urgency.
Frequently asked questions
Do I need to patch if my Devolutions Server is not connected to the internet?
Patching remains advisable. The vulnerability requires authentication, so internal threat and compromised-credential scenarios are still possible. Assume an attacker may gain valid credentials through phishing, credential reuse, or insider access. Isolation reduces risk but does not eliminate it.
Can I prevent the exploit by disabling folder duplication?
Disabling or restricting folder duplication to administrators only can reduce the attack surface significantly. However, this is not a complete fix and may disrupt legitimate workflows. Implement this as a temporary control while you plan and execute patching.
Will patching require downtime?
Likely yes. Devolutions Server updates typically require a brief restart to apply database schema or application changes. Plan a maintenance window during off-hours, and always test in a staging environment first.
What should I look for in my audit logs to see if this was exploited?
Search for folder duplication events (especially by non-admin users), followed by attachment downloads or views from accounts with limited expected permissions. Correlate folder creation timestamps with access logs. High volumes of folder operations by the same user in a short window may indicate reconnaissance or exploitation.
This analysis is based on public CVE and vendor disclosures as of June 2026. No exploit code or detailed weaponization steps are provided. Verify all patch versions, release dates, and affected product versions against the official Devolutions security advisory before implementing changes. If your organization is affected, consult with Devolutions support for environment-specific guidance. SEC.co makes no warranty regarding completeness or real-time accuracy of this intelligence; use it to inform your security program, not as sole decision authority. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10787MEDIUMMissing Authorization in Devolutions Server Deleted User Groups API
- CVE-2022-42479MEDIUMMissing Authorization in TemplateHouse Soledad – MEDIUM Severity Access Control Bypass
- CVE-2022-45813MEDIUMBeRocket Advanced AJAX Product Filters Missing Authorization Flaw
- CVE-2023-25969MEDIUMMissing Authorization in ThemeHunk Contact Form Plugin
- CVE-2023-32959MEDIUMMetroStore Missing Authorization Vulnerability – Patch Guide
- CVE-2025-12714MEDIUMRank Math SEO Plugin Unauthenticated Metadata Injection Vulnerability
- CVE-2025-52766MEDIUMMissing Authorization in Printeers Print & Ship – CVSS 6.5
- CVE-2025-53302MEDIUMMissing Authorization in Anton Shevchuk Constructor Framework