Junglewise Threat Intelligence

CVE-2026-17568: Devolutions Server privilege escalation in role membership management

CVE-2026-17568 · Severity: info · CVSS 7.4 · Published 2026-07-27

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and privileged access, contains a security flaw in how it manages user roles. An authorized user who already has permission to manage group memberships can exploit this flaw to grant themselves full administrator privileges. This could allow a malicious insider to take complete control of the server, access sensitive credentials, and bypass security controls.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the role membership management endpoint of Devolutions Server. The flaw allows an authenticated user who possesses the specific 'user-group membership management' permission to bypass intended restrictions and escalate their privileges to a full administrator. This is achieved by sending a specially crafted API request to the management endpoint. The vulnerability is present in versions 2026.1.23.0 and earlier, as well as 2026.2.4.0 through 2026.2.12.0. Users are advised to upgrade to versions 2026.1.24.0 or 2026.2.14.0 or higher to remediate the issue.

Affected products

  • Devolutions Server 2026.1.23.0 and earlier, 2026.2.4.0 through 2026.2.12.0

Timeline

  • 2026-07-27: advisory: Initial publication of DEVO-2026-0026
  • 2026-07-27: disclosed: CVE-2026-17568 published to NVD

References