Junglewise Threat Intelligence

CVE-2026-12105: Devolutions Server improper access control in folder duplication

CVE-2026-12105 · Severity: info · CVSS 5.3 · Published 2026-06-16

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and privileged credentials, is affected by an access control vulnerability. An authenticated user can gain unauthorized access to file attachments by duplicating folders that have inherited permissions. This could lead to the exposure of sensitive documents or credentials stored as attachments within the platform.

Technical details

An improper access control vulnerability (CWE-862) exists in Devolutions Server versions 2026.2.5 and 2026.1.21 (and earlier). The flaw is triggered when an authenticated user performs a folder duplication operation; the system incorrectly applies inherited permissions, allowing the user to view or retrieve attachments they should not have access to. The attack requires network access and valid user credentials (low privileges). This vulnerability allows for unauthorized information disclosure of stored attachments. Users are advised to upgrade to Devolutions Server 2026.2.7 or 2026.1.22 to remediate the issue.

Affected products

  • Devolutions Devolutions Server 2026.2.5 and earlier, 2026.1.21 and earlier

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory

References