Devolutions Server

10 known vulnerabilities in Devolutions Server, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-93332 CVSS 5.4 medium Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged…
  • CVE-2026-93330 CVSS 4.3 medium Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to…
  • CVE-2026-100289 CVSS 5.0 medium Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated…
  • CVE-2026-100288 CVSS 7.2 high Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read…
  • CVE-2026-100287 CVSS 5.4 medium Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged…
  • CVE-2026-100286 CVSS 6.5 medium Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated…
  • CVE-2026-13327 CVSS 8.3 high Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a…
  • CVE-2026-90971 CVSS 6.5 medium Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a…
  • CVE-2026-90969 CVSS 6.5 medium Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user…
  • CVE-2026-84850 CVSS 4.8 medium Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16…