CVE-2026-93330
Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.
- Published Sep 29, 2026
- CVSS 4.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)