Devolutions
63 known vulnerabilities
Top Products
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20
Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and
Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.
Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Serve
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authen
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.2
Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an aut
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 a
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026
Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows
Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all
Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi
Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authentica
Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an
Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or mo
Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user t
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileg
Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Serv
Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an aut
Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authe
Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authentica
Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the pr
Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce
Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissi
Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated
Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated r
Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory
Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows
Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al
Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authentica
Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacke
Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no add
Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to r
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti
Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra
Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all
Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an
Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att
Frequently Asked Questions
How many CVEs affect Devolutions?
Devolutions has 63 CVE records in our database, including 5 critical and 17 high severity vulnerabilities.
What are the most severe Devolutions vulnerabilities?
Devolutions has 5 critical severity (CVSS 9.0+) and 17 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Devolutions vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Devolutions products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Devolutions Vulnerabilities
CyberStrike scans your infrastructure for Devolutions vulnerabilities and provides real-time remediation guidance.
Get Started