Executive brief
Devolutions Server, a centralized platform for managing remote connections and privileged credentials, contains a security flaw in its entry status management feature. An authenticated user without administrative rights can bypass the required 'Pending Approval' workflow by sending a specially crafted request. This allows unauthorized users to gain access to sensitive entry data that should have required administrator oversight, potentially compromising internal credentials or connection details.
Technical details
A missing authorization vulnerability (CWE-862) exists in the entry status management component of Devolutions Server. The flaw allows an authenticated, low-privileged user to bypass the 'Pending Approval' workflow, which is intended to be an administrator-enforced gate for accessing specific entries. By submitting a crafted status change request, the attacker can manipulate the entry's state to gain unauthorized access to its data. The vulnerability is reachable over the network and requires valid user credentials but no administrative privileges. Devolutions recommends upgrading to version 2026.1.19.0 or 2025.3.22.0 to remediate the issue.
Affected products
- Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier
Timeline
- 2026-05-21: advisory: Initial publication of DEVO-2026-0013 by Devolutions
- 2026-05-22: disclosed: CVE-2026-9251 published to NVD