Devolutions Server PAM Provider Password Rotation Template Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in Devolutions Server within the built-in Privileged Access Management (PAM) provider password rotation templates. This issue allows an authenticated user with write access to a vault to execute arbitrary commands on systems managed by the affected PAM provider. The vulnerability is present in Devolutions Server versions 2026.2.4.0, as well as all versions through 2026.1.20.0.

Impact

Exploitation of this vulnerability could lead to unauthorized command execution on systems managed by the affected PAM provider.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.2.5.0 or higher, or version 2026.1.21.0 or higher.

Added: Jun 8, 2026, 7:30 PM
Updated: Jun 8, 2026, 7:30 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
3.1
exploitability
5.2
remediation
7.7
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.