Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- >= 2026.1.6.0, <= 2026.1.16.0
- <= 2025.3.20.0
A vulnerability exists in Devolutions Server in the user profile update feature, where missing authorization allows authenticated Active Directory users to alter their own profile attributes through a manipulated API request. This issue impacts Devolutions Server versions 2026.1.6.0 to 2026.1.16.0, as well as all versions of Devolutions Server 2025.3.20.0 and earlier.
Exploitation of this vulnerability could lead to unauthorized modification of user profile attributes, potentially allowing users to escalate privileges or gain access to sensitive information.
Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or 2025.3.22.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.