Devolutions Server Incorrect Authorization Vulnerability in PAM Vaults

Vulnerability

A vulnerability exists in Devolutions Server in versions through 2024.3.12, where incorrect authorization in Privileged Access Management (PAM) vaults allows an authenticated user to bypass the 'add in root' permission. This could lead to unauthorized modifications or additions within the PAM vaults, potentially disrupting access management or compliance processes.

Impact

Exploitation of this vulnerability could allow an authenticated user to improperly modify or add entries in PAM vaults, bypassing established permissions. This could undermine the integrity of privileged access management by allowing unauthorized changes to be made, which could be exploited to gain inappropriate access to sensitive resources or systems.

Remediation

Users can upgrade to Devolutions Server version 2024.3.13 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.