Devolutions Server Improper Access Control Vulnerability in PAM Account Discovery Feature

Vulnerability

A vulnerability exists in Devolutions Server versions through 2026.1.19, where improper access control in the PAM account discovery feature allows authenticated users without administrative privileges to delete network discovery scan configurations.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of network discovery scan configurations.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.2.4 or later, or 2026.1.20 or later.

Added: Jun 2, 2026, 4:25 PM
Updated: Jun 2, 2026, 4:25 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.