Executive brief
Devolutions Server, a platform for managing remote connections and privileged passwords, contains a flaw in how it handles 'sealed' entries. An authorized user can bypass the security workflow intended to notify administrators when sensitive data is accessed, allowing them to view protected information without leaving a proper audit trail. This undermines the accountability and compliance monitoring features of the password management system.
Technical details
A vulnerability classified as Improper Enforcement of Behavioral Workflow (CWE-841) exists in the sensitive-data retrieval feature of Devolutions Server. By using a crafted API request, an authenticated user who already has access permissions to a 'sealed' entry can bypass the mandatory unseal workflow. This allows the retrieval of sensitive data without triggering the expected unseal audit notification, effectively circumventing the product's oversight mechanisms. The issue is resolved in Devolutions Server versions 2026.1.19.0 and 2025.3.22.0.
Affected products
- Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier
Timeline
- 2026-05-21: advisory: Initial publication of DEVO-2026-0013 by Devolutions
- 2026-05-22: disclosed: CVE-2026-8477 published to NVD