Junglewise Threat Intelligence

CVE-2026-9249: Devolutions Server unverified password change

CVE-2026-9249 · Severity: low · CVSS 3.1 · Published 2026-05-22

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and passwords, is affected by a security flaw in its password management component. An attacker with low-level access could change a user's password without knowing the original one by sending a specially crafted request. This could lead to unauthorized account access and potential disruption of administrative operations.

Technical details

An unverified password change vulnerability (CWE-620) exists in Devolutions Server. The root cause is a failure to require the current password during a password change request, allowing the process to be completed via a crafted network request. An attacker with low-privileged (PR:L) network access can exploit this to reset user passwords without knowledge of the existing credentials. The vulnerability affects versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. Users are advised to upgrade to Devolutions Server 2026.1.19.0 or 2025.3.22.0 to remediate the issue.

Affected products

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier

Timeline

  • 2026-05-21: advisory: Initial publication of DEVO-2026-0013 by Devolutions Inc.
  • 2026-05-22: disclosed: CVE-2026-9249 published to NVD

References