Executive brief
Devolutions Server, a centralized platform for managing remote connections and privileged access, contains a vulnerability in its password rotation system. An authorized user with permission to manage a vault can exploit this flaw to execute unauthorized commands on the servers managed by the system. This could lead to a full compromise of sensitive infrastructure and the systems being managed by the platform.
Technical details
An OS command injection vulnerability (CWE-78) exists in Devolutions Server due to improper neutralization of special elements within the built-in Privileged Access Management (PAM) provider password rotation templates. An attacker must be authenticated and possess write access to a vault to exploit this vulnerability. By crafting malicious rotation templates, the attacker can achieve arbitrary command execution on the underlying systems managed by the affected PAM provider. The issue is addressed in Devolutions Server versions 2026.2.5.0 and 2026.1.21.0.
Affected products
- Devolutions Devolutions Server 2026.2.4.0, 2026.1.20.0 and earlier
Timeline
- 2026-06-03: advisory: Initial internal publication by Devolutions
- 2026-06-08: disclosed: NVD publication date