Devolutions Server Authorization Bypass Vulnerability in Entry Duplication Feature

Vulnerability

An authorization bypass vulnerability has been identified in the entry duplication feature of Devolutions Server. This issue allows an authenticated user with write access to any vault to duplicate documentation and attachments from an entry in a vault they cannot access, by sending a crafted save request. The vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0, as well as versions 2025.3.20.0 and earlier.

Impact

Exploitation of this vulnerability could lead to unauthorized access to documentation and attachments from entries in restricted vaults.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or 2025.3.22.0 or higher.

Added: May 26, 2026, 3:33 PM
Updated: May 26, 2026, 3:33 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
3.1
exploitability
5.2
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.