Junglewise Threat Intelligence

CVE-2026-7325: Devolutions Server Improper Authorization in Active Directory browsing

CVE-2026-7325 · Severity: high · CVSS 7.1 · Published 2026-05-22

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a platform for managing remote connections and privileged passwords, contains a security flaw in its Active Directory browsing feature. An employee with low-level access could trick the system into sending sensitive login credentials for a high-privileged service account to a server they control. This could allow an attacker to gain elevated access to the organization's identity management infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) / LDAP coercion vulnerability exists in the Active Directory browsing component of Devolutions Server. By exploiting improper authorization checks, a low-privileged authenticated attacker can trigger the server to initiate an LDAP connection to an external, attacker-controlled host. This allows the attacker to perform an authentication relay attack, capturing the authentication material (such as NTLM hashes or Kerberos tickets) associated with the service account used by the Privileged Access Management (PAM) provider. The vulnerability is tracked as CVE-2026-7325 and has been addressed in versions 2026.1.19.0 and 2025.3.22.0.

Affected products

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier

Timeline

  • 2026-05-21: advisory: Initial publication of DEVO-2026-0013 by Devolutions
  • 2026-05-22: disclosed: CVE-2026-7325 published to NVD

References