Junglewise Threat Intelligence

CVE-2026-9223: Devolutions Server missing authorization in vault import feature

CVE-2026-9223 · Severity: medium · CVSS 4.3 · Published 2026-05-22

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and privileged credentials, contains a security flaw in its vault import feature. An authenticated user with low-level permissions can bypass security checks to create new vaults that they should not be authorized to create. This could lead to unauthorized organizational changes or the creation of unmanaged data silos within the platform.

Technical details

An improper access control vulnerability (CWE-284) exists in the vault import functionality of Devolutions Server. The application fails to properly validate the authorization levels of an authenticated user when processing vault import requests. By sending a specially crafted network request to the import endpoint, a low-privileged user can trigger the creation of new vaults, bypassing intended administrative restrictions. This issue is resolved in Devolutions Server version 2026.1.19.0.

Affected products

  • Devolutions Server 2026.1.16.0 and earlier

Timeline

  • 2026-05-21: advisory: Initial publication by Devolutions
  • 2026-05-22: disclosed: NVD publication date

References

Related threats