Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Devolutions

63 known vulnerabilities

5
CRITICAL
17
HIGH
33
MEDIUM
8
LOW

Top Products

devolutions server 49 powershell universal 6 remote desktop manager 5 password manager 1 unigetui 1 hub reporting service 1
63 CVEs · Page 1/2
7.4
CVE-2026-8497

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0

4.3
CVE-2026-17570

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg

4.3
CVE-2026-17569

Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per

8.8
CVE-2026-17568

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm

6.5
CVE-2026-16802

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear

8.8
CVE-2026-16801

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2

8.8
CVE-2026-16800

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20

5.0
CVE-2026-16799

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and

6.5
CVE-2026-16798

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.

3.3
CVE-2026-15642

Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Serve

7.1
CVE-2026-15641

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authen

7.5
CVE-2026-15637

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.2

3.1
CVE-2026-15058

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an aut

8.8
CVE-2026-14536

Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack

6.5
CVE-2026-13437

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 a

7.2
CVE-2026-13372

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026

2.7
CVE-2026-12755

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows

7.5
CVE-2026-10696

Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all

4.3
CVE-2026-12117

Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated

6.5
CVE-2026-12105

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi

4.3
CVE-2026-11890

Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authentica

5.5
CVE-2026-12162

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an

8.8
CVE-2026-12161

Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or mo

4.3
CVE-2026-10787

Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user t

6.5
CVE-2026-10786

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileg

6.5
CVE-2026-10544

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Serv

5.3
CVE-2026-9590

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an aut

5.4
CVE-2026-9522

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authe

5.4
CVE-2026-9251

Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authentica

3.1
CVE-2026-9249

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the pr

2.6
CVE-2026-9248

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce

2.4
CVE-2026-9247

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissi

4.3
CVE-2026-9246

Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated

5.0
CVE-2026-9245

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated r

4.3
CVE-2026-9224

Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory

4.3
CVE-2026-9223

Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged

7.6
CVE-2026-9047

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows

2.7
CVE-2026-8477

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al

7.1
CVE-2026-7325

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authentica

4.3
CVE-2026-5171

Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access

4.3
CVE-2026-5146

Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacke

4.3
CVE-2026-8407

Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no add

6.5
CVE-2026-6706

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to r

5.0
CVE-2026-5175

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti

4.3
CVE-2026-4989

Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate

6.5
CVE-2026-4927

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi

5.0
CVE-2026-4925

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra

8.2
CVE-2026-4924

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all

5.4
CVE-2026-4829

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an

8.2
CVE-2026-4828

Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att

Frequently Asked Questions

How many CVEs affect Devolutions?

Devolutions has 63 CVE records in our database, including 5 critical and 17 high severity vulnerabilities.

What are the most severe Devolutions vulnerabilities?

Devolutions has 5 critical severity (CVSS 9.0+) and 17 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Devolutions vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Devolutions products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Devolutions Vulnerabilities

CyberStrike scans your infrastructure for Devolutions vulnerabilities and provides real-time remediation guidance.

Get Started