Junglewise Threat Intelligence

CVE-2026-12755: Devolutions Server NTLMv2 coercion in PAM AD discovery endpoints

CVE-2026-12755 · Severity: info · CVSS 5.1 · Published 2026-06-25

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a platform for managing remote connections and privileged access, contains a vulnerability in its Active Directory discovery features. An authorized user can trick the server into connecting to a malicious computer, which could allow the attacker to capture sensitive login credentials used by the server. This could lead to further unauthorized access within the corporate network.

Technical details

An improper input validation vulnerability exists in the PAM AD discovery endpoints of Devolutions Server. An authenticated attacker with 'UserGroupsView' permissions can provide a specially crafted 'DomainName' parameter to coerce the server into initiating an authentication request to an attacker-controlled host. This process exposes the PAM provider's credentials as an NTLMv2 challenge-response, which can be captured and potentially cracked or relayed. The issue is fixed in Devolutions Server version 2026.2.9.0.

Affected products

  • Devolutions Server 2026.2.4.0 through 2026.2.7.0

Timeline

  • 2026-06-19: advisory: Initial internal publication by Devolutions
  • 2026-06-25: disclosed: NVD publication date
  • 2026-06-25: patched: Remediation available in version 2026.2.9.0

References