Executive brief
Devolutions Server, a platform for managing remote connections and privileged access, contains a vulnerability in its Active Directory discovery features. An authorized user can trick the server into connecting to a malicious computer, which could allow the attacker to capture sensitive login credentials used by the server. This could lead to further unauthorized access within the corporate network.
Technical details
An improper input validation vulnerability exists in the PAM AD discovery endpoints of Devolutions Server. An authenticated attacker with 'UserGroupsView' permissions can provide a specially crafted 'DomainName' parameter to coerce the server into initiating an authentication request to an attacker-controlled host. This process exposes the PAM provider's credentials as an NTLMv2 challenge-response, which can be captured and potentially cracked or relayed. The issue is fixed in Devolutions Server version 2026.2.9.0.
Affected products
- Devolutions Server 2026.2.4.0 through 2026.2.7.0
Timeline
- 2026-06-19: advisory: Initial internal publication by Devolutions
- 2026-06-25: disclosed: NVD publication date
- 2026-06-25: patched: Remediation available in version 2026.2.9.0