Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2025.2.12.0
A vulnerability exists in Devolutions Server versions through 2025.2.12.0, where improper authorization in the temporary access workflow allows authenticated basic users to self-approve or approve access requests for others. This exploitation can lead to unauthorized access to vaults and entries by sending crafted API requests.
Exploitation of this vulnerability allows for unauthorized access to vaults and entries, potentially leading to unauthorized disclosure or modification of sensitive information.
Users are advised to upgrade to Devolutions Server version 2025.2.14.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.