汇总 Devolutions 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。
已披露问题常与 跨站脚本、SQL 注入与输入验证问题 相关,可能在 生产负载与软件部署 场景中带来 会话劫持与数据泄露 等暴露风险。
相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2026-12117 | Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to which they are not authorized via a crafted API request. | [email protected] | 4.3 | 0.18% | 2026-06-16 | 2026-06-18 |
| CVE-2026-12105 | Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions. | [email protected] | 6.5 | 0.20% | 2026-06-16 | 2026-06-18 |
| CVE-2026-11890 | Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results. | [email protected] | 4.3 | 0.16% | 2026-06-16 | 2026-06-18 |
| CVE-2026-10787 | Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier | [email protected] | 4.3 | 0.15% | 2026-06-08 | 2026-06-12 |
| CVE-2026-10786 | Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier | [email protected] | 6.5 | 0.15% | 2026-06-08 | 2026-06-12 |
| CVE-2026-10544 | Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier | [email protected] | 6.5 | 0.20% | 2026-06-08 | 2026-06-12 |
| CVE-2026-9590 | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission. | [email protected] | 5.3 | 0.18% | 2026-06-02 | 2026-06-02 |
| CVE-2026-9522 | Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations. | [email protected] | 5.4 | 0.14% | 2026-06-02 | 2026-06-02 |
| CVE-2026-5146 | Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.15.0 * Devolutions Server 2025.3.19.0 and earlier | [email protected] | 4.3 | 0.16% | 2026-05-12 | 2026-05-26 |
| CVE-2026-8407 | Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.11.0 * Devolutions Server 2025.3.16.0 and earlier | [email protected] | 4.3 | 0.20% | 2026-05-12 | 2026-05-26 |
| CVE-2026-6706 | Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. This issue affects Server: from 2026.1.6.0 through 2026.1.14.0, through 2025.3.18.0. | [email protected] | 6.5 | 0.20% | 2026-04-28 | 2026-05-04 |
| CVE-2026-5175 | Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests. This issue affects Server: from 2026.1.6 through 2026.1.11. | [email protected] | 5.0 | 0.25% | 2026-04-01 | 2026-04-03 |
| CVE-2026-4989 | Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from 2026.1.1 through 2026.1.11, from 2025.3.1 through 2025.3.17. | [email protected] | 4.3 | 0.16% | 2026-04-01 | 2026-04-03 |
| CVE-2026-4927 | Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11. | [email protected] | 6.5 | 0.22% | 2026-04-01 | 2026-04-03 |
| CVE-2026-4925 | Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. This issue affects Server: from 2026.1.6 through 2026.1.11. | [email protected] | 5.0 | 0.19% | 2026-04-01 | 2026-04-03 |
| CVE-2026-4924 | Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially authenticated session token. | [email protected] | 8.2 | 0.33% | 2026-04-01 | 2026-04-03 |
| CVE-2026-4829 | Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow. | [email protected] | 5.4 | 0.17% | 2026-04-01 | 2026-04-03 |
| CVE-2026-4828 | Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request. | [email protected] | 8.2 | 0.26% | 2026-04-01 | 2026-04-03 |
| CVE-2026-4434 | Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. | [email protected] | 8.1 | 0.14% | 2026-03-20 | 2026-03-30 |
| CVE-2026-4396 | Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. | [email protected] | 8.1 | 0.14% | 2026-03-18 | 2026-03-30 |