Junglewise Threat Intelligence

CVE-2026-9522: Devolutions Server improper access control in PAM account discovery

CVE-2026-9522 · Severity: info · CVSS 5.4 · Published 2026-06-02

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and privileged accounts, contains a security flaw in its account discovery feature. An authenticated user without administrative rights can delete network discovery scan configurations. This could disrupt IT operations by removing automated processes used to identify and manage accounts across the network.

Technical details

An improper access control vulnerability exists within the Privileged Access Management (PAM) account discovery component of Devolutions Server. The flaw resides in the permission validation logic, which fails to properly restrict deletion actions to administrative users. An attacker with standard authenticated access can exploit this over the network to delete existing network discovery scan configurations. This results in a loss of integrity and availability for automated discovery tasks. The issue is addressed in Devolutions Server versions 2026.2.4, 2026.1.20, or later.

Affected products

  • Devolutions Devolutions Server 2026.1.19 and earlier

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References