devolutions
29 known vulnerabilities affecting devolutions products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-9047 | Medium | 0.3% | 7.6 | Improper handling of factor key state in the multi-factor authentication managem… | |
| CVE-2026-16800 | Medium | 0.3% | 8.8 | Improper control of generation of code ('Code Injection') in the schedule featur… | |
| CVE-2026-16801 | Medium | 0.3% | 8.8 | Improper control of generation of code ('Code Injection') in the variables featu… | |
| CVE-2026-15641 | Medium | 0.3% | 7.1 | Improper authorization in the access request status endpoint in Devolutions Serv… | |
| CVE-2026-15637 | Medium | 0.3% | 7.5 | Improper authorization in the PAM SSH key and certificate retrieval endpoints i… | |
| CVE-2026-7325 | Medium | 0.2% | 7.1 | Improper authorization in the Active Directory browsing feature in Devolutions S… | |
| CVE-2026-17568 | Medium | 0.2% | 8.8 | Improper access control in the role membership management endpoint in Devolution… | |
| CVE-2026-8497 | Medium | 0.1% | 7.4 | Improper certificate validation in the Devolutions Server connection handling in… | |
| CVE-2026-8477 | Low | 0.2% | 2.7 | Improper enforcement of the sealed-entry workflow in the entry sensitive-data re… | |
| CVE-2026-5171 | Low | 0.2% | 4.3 | Improper access control in the entry activity log feature in Devolutions Server … | |
| CVE-2026-9245 | Low | 0.2% | 5.0 | Improper input validation in the external authentication provider flow in Devolu… | |
| CVE-2026-16798 | Low | 0.2% | 6.5 | Insertion of sensitive information into sent data in the automation jobs API in … | |
| CVE-2026-9247 | Low | 0.2% | 2.4 | Insufficient logging in the entry export feature in Devolutions Server allows an… | |
| CVE-2026-9223 | Low | 0.2% | 4.3 | Missing authorization in the vault import feature in Devolutions Server 2026.1.… | |
| CVE-2026-9224 | Low | 0.2% | 4.3 | Missing authorization in the user profile update feature in Devolutions Server a… | |
| CVE-2026-9246 | Low | 0.2% | 4.3 | Improper access control in the entry documentation and attachment features in De… | |
| CVE-2026-15058 | Low | 0.2% | 3.1 | Improper authorization in the secure messages deletion endpoint in Devolutions S… | |
| CVE-2026-10544 | Low | 0.2% | 6.5 | Improper neutralization of special elements in the built-in PAM provider passwor… | |
| CVE-2026-9251 | Low | 0.2% | 5.4 | Missing authorization in the entry status management feature in Devolutions Serv… | |
| CVE-2026-9248 | Low | 0.2% | 2.6 | Authorization bypass in the entry duplication feature in Devolutions Server allo… | |
| CVE-2026-9249 | Low | 0.2% | 3.1 | Unverified password change in Devolutions Server allows an attacker to change a … | |
| CVE-2026-9590 | Low | 0.2% | 5.3 | Improper access control in the permission validation component in Devolutions Se… | |
| CVE-2026-17569 | Low | 0.2% | 4.3 | Improper access control in the NetBox synchronizer in Devolutions Server allows … | |
| CVE-2026-17570 | Low | 0.2% | 4.3 | Improper access control in the PAM password history endpoints in Devolutions Ser… | |
| CVE-2026-10787 | Low | 0.2% | 4.3 | Missing authorization in the deleted user groups API in Devolutions Server allow… | |
| CVE-2026-16799 | Low | 0.2% | 5.0 | Improper access control in the automation tests and workflows features in Devolu… | |
| CVE-2026-10786 | Low | 0.1% | 6.5 | Improper access control in the ticketing integration settings in Devolutions Ser… | |
| CVE-2026-9522 | Low | 0.1% | 5.4 | Improper access control in the PAM account discovery feature in Devolutions Serv… | |
| CVE-2026-16802 | Low | 0.1% | 6.5 | Cleartext storage of sensitive information in the variables feature in Devolutio… |