Executive brief
Devolutions Server, a centralized platform for managing remote connections and passwords, is affected by a security flaw in its password management component. An attacker with low-level access could change a user's password without knowing the original one by sending a specially crafted request. This could lead to unauthorized account access and potential disruption of administrative operations.
Technical details
An unverified password change vulnerability (CWE-620) exists in Devolutions Server. The root cause is a failure to require the current password during a password change request, allowing the process to be completed via a crafted network request. An attacker with low-privileged (PR:L) network access can exploit this to reset user passwords without knowledge of the existing credentials. The vulnerability affects versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. Users are advised to upgrade to Devolutions Server 2026.1.19.0 or 2025.3.22.0 to remediate the issue.
Affected products
- Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier
Timeline
- 2026-05-21: advisory: Initial publication of DEVO-2026-0013 by Devolutions Inc.
- 2026-05-22: disclosed: CVE-2026-9249 published to NVD