Junglewise Threat Intelligence

CVE-2026-9246: Devolutions Server improper access control in sealed entries documentation

CVE-2026-9246 · Severity: medium · CVSS 4.3 · Published 2026-05-22

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and privileged credentials, contains a security flaw in its documentation and attachment handling. An authorized user with basic read access to a vault can bypass security restrictions to view sensitive documents and attachments that are supposed to be 'sealed' or locked. This could lead to the unauthorized disclosure of confidential operational procedures or sensitive files stored within the server.

Technical details

An improper access control vulnerability (CWE-862) exists in the entry documentation and attachment features of Devolutions Server. The flaw resides in how the application validates permissions for 'sealed' entries when accessed via the API. An attacker with valid credentials and 'vault read' permissions can bypass the 'sealed' status restriction by sending a specially crafted API request to the server. This allows the retrieval of sensitive attachments and documentation that should otherwise be inaccessible. The issue is resolved in Devolutions Server versions 2025.3.22.0 and 2026.1.19.0.

Affected products

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier

Timeline

  • 2026-05-21: advisory: Initial publication by Devolutions
  • 2026-05-22: disclosed: CVE published to NVD

References