Junglewise Threat Intelligence

CVE-2026-9248: Devolutions Server authorization bypass in entry duplication

CVE-2026-9248 · Severity: low · CVSS 2.6 · Published 2026-05-22

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server is a centralized platform used by IT teams to manage remote connections and privileged credentials. A security flaw in the entry duplication feature allows a user who has permission to edit at least one vault to bypass security restrictions and copy sensitive documentation or attachments from other vaults they are not authorized to access. This could lead to the unauthorized disclosure of internal technical documentation or sensitive files stored within the server.

Technical details

An authorization bypass vulnerability (CWE-639) exists in the entry duplication feature of Devolutions Server. The flaw is triggered when an authenticated user with write access to at least one vault submits a specially crafted save request. By manipulating the request, the attacker can instruct the server to copy documentation and attachments from an entry located in a vault for which they lack access permissions. This vulnerability requires the attacker to have valid credentials and existing write permissions to at least one vault. The issue is addressed in Devolutions Server versions 2026.1.19.0 and 2025.3.22.0.

Affected products

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0; 2025.3.20.0 and earlier

Timeline

  • 2026-05-21: advisory: Initial publication by Devolutions
  • 2026-05-22: disclosed: NVD publication date

References