Executive brief
Devolutions Server, a centralized platform for managing remote connections and privileged access, contains a security flaw in its permission validation system. This vulnerability allows an authorized user who already has basic editing rights to modify sensitive asset information they should not be able to access. This could lead to unauthorized changes in the IT infrastructure management environment, potentially compromising operational integrity.
Technical details
An improper access control vulnerability exists within the permission validation component of Devolutions Server. The flaw allows an authenticated attacker with 'entry edit' privileges to bypass intended restrictions and modify asset information without possessing the specific required permissions for those assets. The vulnerability is reachable over the network and requires basic user authentication. Devolutions has addressed this issue in versions 2026.2.4 and 2026.1.20.
Affected products
- Devolutions Devolutions Server 2026.1.19 and earlier
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory