Executive brief
Devolutions Server, a self-hosted platform for managing credentials and privileged access, contains a security flaw in its Privileged Access Management (PAM) module. An authenticated user with basic access can bypass security checks to view sensitive one-time password (OTP) secret keys and recovery codes that they should not be able to see. This could allow an unauthorized individual to bypass multi-factor authentication for protected accounts, potentially leading to unauthorized access to sensitive corporate systems.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Privileged Access Management (PAM) module of Devolutions Server. The flaw is located within the PAM API endpoints, which fail to properly validate user permissions before disclosing sensitive authentication data. An attacker with a valid PAM license and basic authenticated access can send crafted requests to these endpoints to retrieve OTP secret keys and recovery codes. This information can be used to bypass two-factor authentication mechanisms for managed accounts. The issue affects versions 2026.1.6.0 through 2026.1.11.0 and versions 2025.3.16.0 and earlier.
Affected products
- Devolutions Devolutions Server 2026.1.6.0 through 2026.1.11.0, 2025.3.16.0 and earlier
Timeline
- 2026-04-01: advisory: Initial publication of DEVO-2026-0010
- 2026-05-12: disclosed: CVE-2026-8407 added to advisory