Devolutions Server Improper Enforcement of Behavioral Controls Vulnerability Allowing Unauthorized PAM Account Deletion

Vulnerability

A vulnerability exists in Devolutions Server versions through 2025.3.15 that allows an authenticated attacker with delete permissions to improperly delete Privileged Access Management (PAM) accounts. This is achieved by selecting a checked-out account alongside at least one non-checked-out account and performing a bulk deletion. This flaw bypasses intended safeguards, disrupts Just-in-Time (JIT) privilege revocation, and could lead to persistent elevated privileges.

Impact

Exploitation of this vulnerability could result in the unauthorized deletion of PAM accounts, particularly those currently checked out, potentially allowing for the retention of elevated privileges.

Remediation

Users are advised to upgrade to Devolutions Server version 2025.3.16 or 2026.1.

Added: Mar 3, 2026, 10:50 PM
Updated: Mar 3, 2026, 10:50 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
4.8
remediation
8.3
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.