Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- 2026.2.4.0
- 2026.1.20.0
A command injection vulnerability has been identified in Devolutions Server within the built-in Privileged Access Management (PAM) provider password rotation templates. This issue allows an authenticated user with write access to a vault to execute arbitrary commands on systems managed by the affected PAM provider. The vulnerability is present in Devolutions Server versions 2026.2.4.0, as well as all versions through 2026.1.20.0.
Exploitation of this vulnerability could lead to unauthorized command execution on systems managed by the affected PAM provider.
Users are advised to upgrade to Devolutions Server version 2026.2.5.0 or higher, or version 2026.1.21.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.