📦 Devolutions Server

by Devolutions

🔍 What is Devolutions Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-2921

CRITICAL CVSS 9.8 Mar 26, 2024

This vulnerability allows authenticated users with PAM access in Devolutions Server to bypass permission controls and view unauthorized PAM entries. It affects all Devolutions Server deployments runni...

CVE-2021-23921

CRITICAL CVSS 9.1 Apr 1, 2021

This vulnerability in Devolutions Server allows attackers to bypass access controls on Password List entries, potentially exposing sensitive credentials. It affects all Devolutions Server installation...

CVE-2025-13757

HIGH CVSS 8.8 Nov 27, 2025

An SQL injection vulnerability in the last usage logs feature of Devolutions Server allows attackers to execute arbitrary SQL commands. This affects all Devolutions Server installations up to specific...

CVE-2025-11619

HIGH CVSS 8.8 Oct 15, 2025

CVE-2025-11619 is an improper certificate validation vulnerability in Devolutions Server that allows man-in-the-middle attackers to intercept encrypted traffic between clients and gateways. This affec...

CVE-2025-8312

HIGH CVSS 7.1 Jul 30, 2025

A deadlock in the PAM automatic check-in feature of Devolutions Server allows passwords to remain valid beyond their intended check-out period. This affects organizations using Devolutions Server for ...

CVE-2025-4433

HIGH CVSS 8.8 May 30, 2025

This vulnerability allows non-administrative users with both 'User Management' and 'User Group Management' permissions in Devolutions Server to escalate privileges by adding themselves or others to ad...

CVE-2025-2277

HIGH CVSS 7.5 Mar 13, 2025

This vulnerability in Devolutions Server exposes SSH passwords in the web-based authentication component due to missing password masking. An authenticated user could inadvertently leak their SSH passw...

CVE-2025-2280

HIGH CVSS 8.1 Mar 13, 2025

This vulnerability allows authenticated users in Devolutions Server to bypass browser extension restrictions, potentially enabling malicious browser extensions to interact with the application. It aff...

CVE-2024-2915

HIGH CVSS 8.8 Mar 26, 2024

This vulnerability allows attackers with access to Devolutions Server's PAM JIT elevation feature to escalate privileges to unauthorized groups via crafted requests. It affects Devolutions Server 2024...

CVE-2024-1764

HIGH CVSS 7.6 Mar 5, 2024

This vulnerability allows users in Devolutions Server to retain elevated privileges beyond their intended expiration time. Attackers could exploit this to maintain unauthorized access to sensitive sys...

CVE-2023-5240

HIGH CVSS 7.5 Oct 13, 2023

This vulnerability allows attackers with permission to manage PAM propagation scripts in Devolutions Server to retrieve stored passwords via a GET request. It affects Devolutions Server 2023.2.8.0 and...

CVE-2023-0953

HIGH CVSS 8.8 Mar 1, 2023

This SQL injection vulnerability in Devolutions Server allows authenticated attackers to execute arbitrary SQL commands through insufficient input sanitization in the documentation feature. Attackers ...

CVE-2021-28157

HIGH CVSS 7.2 Apr 14, 2021

This SQL injection vulnerability in Devolutions Server allows administrative users to execute arbitrary SQL commands via the username parameter in the user deletion API endpoint. It affects Devolution...

CVE-2021-23923

HIGH CVSS 8.1 Apr 1, 2021

This vulnerability allows Windows domain users to bypass authentication in Devolutions Server, potentially gaining unauthorized access. It affects organizations using Devolutions Server with Windows d...

CVE-2026-3221

MEDIUM CVSS 4.9 Feb 25, 2026

Devolutions Server versions 2025.3.14 and earlier store sensitive user account information unencrypted in the database. This allows attackers with database access to read sensitive user data directly....

CVE-2025-13683

MEDIUM CVSS 6.5 Nov 28, 2025

This vulnerability in Devolutions Server and Remote Desktop Manager exposes credentials through unintended requests, potentially allowing attackers to access sensitive authentication data. It affects ...

CVE-2025-13765

MEDIUM CVSS 4.3 Nov 27, 2025

CVE-2025-13765 allows non-administrative users in Devolutions Server to access email service credentials, potentially exposing sensitive authentication information. This affects Devolutions Server ins...

CVE-2025-12808

MEDIUM CVSS 6.5 Nov 6, 2025

An improper access control vulnerability in Devolutions Server allows users with 'View-only' permissions to access sensitive nested password fields they shouldn't have access to, potentially exposing ...

CVE-2025-11958

MEDIUM CVSS 4.1 Oct 22, 2025

An improper input validation vulnerability in Devolutions Server's Security Dashboard ignored-tasks API allows authenticated users to send crafted requests that cause denial of service to the Security...

CVE-2025-0691

MEDIUM CVSS 5.0 Jun 5, 2025

This vulnerability allows authenticated users in Devolutions Server to bypass client-side validation and edit permissions they shouldn't have access to. It affects all Devolutions Server installations...

CVE-2025-4493

MEDIUM CVSS 6.5 May 28, 2025

This vulnerability allows a PAM (Privileged Access Management) user in Devolutions Server to perform JIT (Just-In-Time) privilege requests on groups they shouldn't have access to. It's caused by an im...

CVE-2025-2278

MEDIUM CVSS 6.5 Mar 13, 2025

This vulnerability allows authenticated users in Devolutions Server to access temporary access and checkout request information by guessing or knowing request IDs. It affects all Devolutions Server de...

CVE-2024-12196

MEDIUM CVSS 6.5 Dec 4, 2024

This vulnerability allows authenticated users in Devolutions Server to view password history entries without proper authorization. Attackers with valid credentials can access sensitive password histor...

CVE-2024-10971

MEDIUM CVSS 4.3 Nov 12, 2024

This vulnerability allows authenticated users in Devolutions DVLS to bypass intended access controls and view password history data they shouldn't have permission to access. It affects all users with ...

CVE-2024-6512

MEDIUM CVSS 6.5 Sep 25, 2024

This CVE describes an authorization bypass vulnerability in Devolutions Server's PAM access request approval mechanism. Authenticated users with approval permissions can approve their own access reque...

CVE-2024-4846

MEDIUM CVSS 6.3 Jun 25, 2024

This vulnerability allows an authenticated attacker to bypass two-factor authentication (2FA) in Devolutions Server by using another browser tab to authenticate as another user without being prompted ...

CVE-2024-5072

MEDIUM CVSS 6.5 May 17, 2024

This vulnerability allows authenticated users with PAM JIT elevation access in Devolutions Server to manipulate LDAP filter queries through crafted requests. Attackers could potentially access unautho...

CVE-2025-13758

LOW CVSS 3.5 Nov 27, 2025

Devolutions Server versions through 2025.2.20 and 2025.3.8 expose credentials in unintended requests, potentially leaking sensitive authentication data. This affects all users running vulnerable versi...