Executive brief
Devolutions Server, a centralized platform for managing remote connections and privileged credentials, contains a security flaw in its documentation and attachment handling. An authorized user with basic read access to a vault can bypass security restrictions to view sensitive documents and attachments that are supposed to be 'sealed' or locked. This could lead to the unauthorized disclosure of confidential operational procedures or sensitive files stored within the server.
Technical details
An improper access control vulnerability (CWE-862) exists in the entry documentation and attachment features of Devolutions Server. The flaw resides in how the application validates permissions for 'sealed' entries when accessed via the API. An attacker with valid credentials and 'vault read' permissions can bypass the 'sealed' status restriction by sending a specially crafted API request to the server. This allows the retrieval of sensitive attachments and documentation that should otherwise be inaccessible. The issue is resolved in Devolutions Server versions 2025.3.22.0 and 2026.1.19.0.
Affected products
- Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier
Timeline
- 2026-05-21: advisory: Initial publication by Devolutions
- 2026-05-22: disclosed: CVE published to NVD