Executive brief
Devolutions Server, a platform used for managing privileged access and credentials, contains a security flaw in how it handles SSH keys and certificates. An authorized user with low-level permissions can exploit this to view and steal private keys they are not supposed to access. This could allow an attacker to impersonate legitimate users and gain unauthorized access to other sensitive systems across the corporate network.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the PAM SSH key and certificate retrieval endpoints of Devolutions Server. The root cause is improper authorization checks when a user requests a specific credential identifier. An authenticated attacker with low privileges can bypass intended access controls by directly referencing a credential ID to retrieve the associated private key. This vulnerability affects versions 2026.1.22 and earlier, as well as 2026.2.11 and earlier. The issue is resolved in versions 2026.1.23.0 and 2026.2.12.0.
Affected products
- Devolutions Server 2026.1.22 and earlier, 2026.2.11 and earlier
Timeline
- 2026-07-14: advisory
- 2026-07-14: disclosed