Executive brief
Devolutions Server is a centralized platform used by IT teams to manage remote connections and privileged credentials. A security flaw in the Privileged Access Management (PAM) component allows logged-in users to view the results of account discovery scans they should not have access to. This could lead to the unauthorized disclosure of sensitive information regarding the organization's network accounts and infrastructure.
Technical details
An improper access control vulnerability exists in Devolutions Server within the Privileged Access Management (PAM) account discovery feature. The flaw allows an authenticated attacker with low privileges to bypass intended access restrictions and retrieve the results of account discovery scans via the network. This vulnerability is categorized under CWE-882 (Improper Handling of Connection Parameter Modification). An exploit could result in the exposure of discovered account names and related metadata. The issue is resolved in Devolutions Server versions 2026.2.7 and 2026.1.22.
Affected products
- Devolutions Devolutions Server 2026.2.5 and earlier, 2026.1.21 and earlier
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory