Junglewise Threat Intelligence

CVE-2026-9224: Devolutions Server missing authorization in user profile update

CVE-2026-9224 · Severity: medium · CVSS 4.3 · Published 2026-05-22

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and credentials, contains a security flaw in its user profile update feature. This vulnerability allows an authenticated employee to modify their own profile attributes in ways that should normally be restricted. While this does not grant access to other users' data, it could allow an individual to bypass certain organizational profile policies or data integrity controls.

Technical details

A missing authorization vulnerability (CWE-862) exists in the user profile update component of Devolutions Server. An authenticated attacker with Active Directory credentials can bypass intended restrictions by sending a specially crafted API request to modify their own profile attributes. The attack is carried out over the network and requires low privileges (standard user authentication). While the impact is limited to the attacker's own profile, it represents a failure in server-side authorization logic. The issue is addressed in Devolutions Server versions 2026.1.19.0 and 2025.3.22.0.

Affected products

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier

Timeline

  • 2026-05-21: disclosed: Initial publication of vendor advisory DEVO-2026-0013
  • 2026-05-22: advisory: NVD publication date

References