Executive brief
Devolutions Server, a centralized platform for managing remote connections and credentials, contains a security flaw in its social login component. An authorized user within the system can bypass access controls to view metadata about social login entries they are not supposed to see. While this does not grant direct access to accounts, it allows for the unauthorized collection of internal configuration details.
Technical details
An improper access control vulnerability (CWE-200) exists in the social login connection endpoint of Devolutions Server. An authenticated vault member can send a crafted API request to the server to enumerate metadata for social login entries that they are not authorized to access. This vulnerability stems from insufficient validation of user permissions at the specific API endpoint. An attacker with low-level authenticated access can exploit this to gather information about the environment's configuration. The issue is addressed in Devolutions Server versions 2026.2.7 and 2026.1.22.
Affected products
- Devolutions Devolutions Server 2026.2.5 and earlier, 2026.1.21 and earlier
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory