Devolutions Server Improper Authorization Vulnerability in Active Directory Browsing Feature Allowing Authentication Material Relay

Vulnerability

A vulnerability exists in the Active Directory browsing feature of Devolutions Server, specifically in versions 2026.1.6.0 through 2026.1.16.0 and 2025.3.20.0 and earlier. This vulnerability allows a low-privileged authenticated user to improperly obtain authentication material related to a stored Privileged Access Management (PAM) provider service account. The issue arises from an authorization flaw that enables the relay of authentication data to an attacker-controlled server.

Impact

Exploitation of this vulnerability could lead to unauthorized access to authentication materials, potentially allowing for further exploitation of PAM provider service accounts.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or 2025.3.22.0 or higher.

Added: May 26, 2026, 3:42 PM
Updated: May 26, 2026, 3:42 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.