Executive brief
Devolutions Server, a centralized platform for managing remote connections and credentials, contains a security flaw in its user group management interface. An authenticated user with low-level permissions can access information about deleted user groups that they should not be able to see. While this does not allow for the modification of data, it results in the unauthorized disclosure of organizational metadata.
Technical details
A missing authorization check (CWE-862) exists within the deleted user groups API endpoint of Devolutions Server. An attacker must be authenticated with at least low-privileged access to the server. By sending a specially crafted API request, the attacker can bypass intended access controls to enumerate and retrieve metadata associated with user groups that have been deleted. The vulnerability is present in versions 2026.2.4.0 and 2026.1.20.0 and earlier. Users are advised to upgrade to versions 2026.2.5.0 or 2026.1.21.0 to remediate the issue.
Affected products
- Devolutions Devolutions Server 2026.2.4.0, 2026.1.20.0 and earlier
Timeline
- 2026-06-03: advisory: Initial publication by Devolutions
- 2026-06-08: disclosed: NVD publication date