Devolutions Server Privilege Escalation Vulnerability in User Group Management

Vulnerability

A privilege escalation vulnerability has been identified in Devolutions Server versions through 2025.1.7.0. The issue arises from improper access control in user group management, allowing non-administrative users with 'User Management' and 'User Group Management' permissions to add users to groups with administrative privileges.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling users to gain administrative rights they should not have.

Remediation

Users are advised to upgrade to Devolutions Server version 2025.1.9.0 or higher.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.