Devolutions Security Vulnerabilities (CVEs)

Track 45 security vulnerabilities affecting Devolutions products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

6 Critical
21 High
17 Medium
1 Low
🔔 Get Alerts for Devolutions
CVE-2026-3221 4.9

Devolutions Server versions 2025.3.14 and earlier store sensitive user account information unencrypted in the database. This allows attackers with dat...

Feb 25, 2026
CVE-2025-13683 6.5

This vulnerability in Devolutions Server and Remote Desktop Manager exposes credentials through unintended requests, potentially allowing attackers to...

Nov 28, 2025
CVE-2025-13757 8.8

An SQL injection vulnerability in the last usage logs feature of Devolutions Server allows attackers to execute arbitrary SQL commands. This affects a...

Nov 27, 2025
CVE-2025-13758 3.5

Devolutions Server versions through 2025.2.20 and 2025.3.8 expose credentials in unintended requests, potentially leaking sensitive authentication dat...

Nov 27, 2025
CVE-2025-13765 4.3

CVE-2025-13765 allows non-administrative users in Devolutions Server to access email service credentials, potentially exposing sensitive authenticatio...

Nov 27, 2025
CVE-2025-12808 6.5

An improper access control vulnerability in Devolutions Server allows users with 'View-only' permissions to access sensitive nested password fields th...

Nov 6, 2025
CVE-2025-11958 4.1

An improper input validation vulnerability in Devolutions Server's Security Dashboard ignored-tasks API allows authenticated users to send crafted req...

Oct 22, 2025
CVE-2025-11619 8.8

CVE-2025-11619 is an improper certificate validation vulnerability in Devolutions Server that allows man-in-the-middle attackers to intercept encrypte...

Oct 15, 2025
CVE-2025-8312 7.1

A deadlock in the PAM automatic check-in feature of Devolutions Server allows passwords to remain valid beyond their intended check-out period. This a...

Jul 30, 2025
CVE-2025-0691 5.0

This vulnerability allows authenticated users in Devolutions Server to bypass client-side validation and edit permissions they shouldn't have access t...

Jun 5, 2025
CVE-2025-4433 8.8

This vulnerability allows non-administrative users with both 'User Management' and 'User Group Management' permissions in Devolutions Server to escala...

May 30, 2025
CVE-2025-5334 7.5

This vulnerability in Devolutions Remote Desktop Manager allows authenticated users to access private personal information when entries are unintentio...

May 29, 2025
CVE-2025-4493 6.5

This vulnerability allows a PAM (Privileged Access Management) user in Devolutions Server to perform JIT (Just-In-Time) privilege requests on groups t...

May 28, 2025
CVE-2025-2562 5.4

This vulnerability in Devolutions Remote Desktop Manager allows authenticated users to use stored passwords via the autotyping feature without generat...

Mar 26, 2025
CVE-2025-2277 7.5

This vulnerability in Devolutions Server exposes SSH passwords in the web-based authentication component due to missing password masking. An authentic...

Mar 13, 2025
CVE-2025-2278 6.5

This vulnerability allows authenticated users in Devolutions Server to access temporary access and checkout request information by guessing or knowing...

Mar 13, 2025
CVE-2025-2280 8.1

This vulnerability allows authenticated users in Devolutions Server to bypass browser extension restrictions, potentially enabling malicious browser e...

Mar 13, 2025
CVE-2025-1635 6.5

This vulnerability in Devolutions Remote Desktop Manager allows authenticated users to export hub data sources containing their authenticated session ...

Mar 13, 2025
CVE-2025-1193 8.1

CVE-2025-1193 is a certificate validation vulnerability in Devolutions Remote Desktop Manager that allows man-in-the-middle attacks. Attackers can int...

Feb 10, 2025
CVE-2024-11621 8.8

This vulnerability allows attackers to perform man-in-the-middle attacks by intercepting and modifying encrypted communications in Devolutions Remote ...

Feb 10, 2025
CVE-2024-12196 6.5

This vulnerability allows authenticated users in Devolutions Server to view password history entries without proper authorization. Attackers with vali...

Dec 4, 2024
CVE-2024-12149 8.1

This vulnerability allows authenticated users in Devolutions Remote Desktop Manager to request temporary permissions on entries and receive higher pri...

Dec 4, 2024
CVE-2024-11671 5.4

This vulnerability allows authenticated users in Devolutions Remote Desktop Manager to bypass multi-factor authentication (MFA) by switching data sour...

Nov 25, 2024
CVE-2024-10971 4.3

This vulnerability allows authenticated users in Devolutions DVLS to bypass intended access controls and view password history data they shouldn't hav...

Nov 12, 2024
CVE-2024-6512 6.5

This CVE describes an authorization bypass vulnerability in Devolutions Server's PAM access request approval mechanism. Authenticated users with appro...

Sep 25, 2024
CVE-2024-6354 7.2

This vulnerability allows authenticated users in Devolutions Remote Desktop Manager to bypass execute permissions through the PAM dashboard. Attackers...

Jun 26, 2024
CVE-2024-4846 6.3

This vulnerability allows an authenticated attacker to bypass two-factor authentication (2FA) in Devolutions Server by using another browser tab to au...

Jun 25, 2024
CVE-2024-6055 4.7

This vulnerability in Devolutions Remote Desktop Manager allows attackers who obtain exported configuration files to recover PowerShell credentials st...

Jun 17, 2024
CVE-2024-6057 9.8

This vulnerability allows attackers who have already compromised access to a Devolutions Remote Desktop Manager instance to bypass the vault master pa...

Jun 17, 2024
CVE-2024-5072 6.5

This vulnerability allows authenticated users with PAM JIT elevation access in Devolutions Server to manipulate LDAP filter queries through crafted re...

May 17, 2024
CVE-2024-2915 8.8

This vulnerability allows attackers with access to Devolutions Server's PAM JIT elevation feature to escalate privileges to unauthorized groups via cr...

Mar 26, 2024
CVE-2024-2921 9.8

This vulnerability allows authenticated users with PAM access in Devolutions Server to bypass permission controls and view unauthorized PAM entries. I...

Mar 26, 2024
CVE-2024-1764 7.6

This vulnerability allows users in Devolutions Server to retain elevated privileges beyond their intended expiration time. Attackers could exploit thi...

Mar 5, 2024
CVE-2023-6593 9.8

This vulnerability allows attackers with physical or application access to an iOS device running Devolutions Remote Desktop Manager to bypass client-s...

Dec 12, 2023
CVE-2023-6288 7.8

This vulnerability allows attackers to inject malicious code into Remote Desktop Manager on macOS by manipulating the DYLIB_INSERT_LIBRARIES environme...

Dec 6, 2023
CVE-2023-5765 9.8

This vulnerability allows attackers to bypass access controls in Devolutions Remote Desktop Manager by switching data sources in the password analyzer...

Nov 1, 2023
CVE-2023-5240 7.5

This vulnerability allows attackers with permission to manage PAM propagation scripts in Devolutions Server to retrieve stored passwords via a GET req...

Oct 13, 2023
CVE-2023-4373 9.8

This vulnerability in Devolutions Remote Desktop Manager allows users to bypass permission checks when using remote tools and macros, enabling unautho...

Aug 21, 2023
CVE-2023-1580 7.5

This vulnerability allows attackers to cause denial of service by exploiting uncontrolled resource consumption in Devolutions Gateway's logging featur...

Apr 2, 2023
CVE-2023-0953 8.8

This SQL injection vulnerability in Devolutions Server allows authenticated attackers to execute arbitrary SQL commands through insufficient input san...

Mar 1, 2023
CVE-2022-33995 7.5

This path traversal vulnerability in Devolutions Remote Desktop Manager allows attackers to create or overwrite arbitrary files on the system by manip...

Jun 21, 2022
CVE-2021-42098 8.8

This vulnerability in Devolutions Remote Desktop Manager allows attackers to bypass permission checks via batch custom PowerShell scripts. Attackers c...

Oct 18, 2021
CVE-2021-28157 7.2

This SQL injection vulnerability in Devolutions Server allows administrative users to execute arbitrary SQL commands via the username parameter in the...

Apr 14, 2021
CVE-2021-23921 9.1

This vulnerability in Devolutions Server allows attackers to bypass access controls on Password List entries, potentially exposing sensitive credentia...

Apr 1, 2021
CVE-2021-23923 8.1

This vulnerability allows Windows domain users to bypass authentication in Devolutions Server, potentially gaining unauthorized access. It affects org...

Apr 1, 2021

Why Monitor Devolutions Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 45+ known vulnerabilities affecting Devolutions products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Devolutions packages in under 60 seconds. No agents required - completely agentless scanning that works across Devolutions deployments.

Free vulnerability database: Access detailed information about every Devolutions CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Devolutions CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Devolutions CVEs Free