Executive brief
Devolutions Server, a platform for managing remote connections and privileged access, contains a security flaw that allows users to bypass administrative oversight. A low-privileged user can exploit this vulnerability to approve their own requests for access to sensitive systems or credentials without the required manager review. This undermines the security controls intended to prevent unauthorized access to corporate infrastructure.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the access request status endpoint of Devolutions Server. The flaw allows an authenticated user with low privileges to issue a direct call to the request status endpoint to self-approve a pending access request, effectively bypassing the mandatory administrative review process. The vulnerability affects versions 2026.1.22 and earlier, as well as 2026.2.11 and earlier. A fix is available in versions 2026.1.23.0 and 2026.2.12.0.
Affected products
- Devolutions Server 2026.1.22 and earlier, 2026.2.11 and earlier
Timeline
- 2026-07-14: advisory
- 2026-07-14: disclosed