CVE-2025-11957

8.4

Devolutions · Devolutions Server

An improper authorization flaw in Devolutions Server allows authenticated users to approve their own or others' temporary access requests, leading to unauthorized vault access.

Executive summary

A critical authorization bypass vulnerability in Devolutions Server allows authenticated users to escalate privileges and access sensitive credentials via API manipulation.

Vulnerability

This is an authorization bypass vulnerability (CWE-639) where an authenticated basic user can manipulate the temporary access workflow to self-approve or approve requests for other users. By sending crafted API requests, an attacker can gain unauthorized access to vaults and sensitive entries.

Business impact

The ability for a standard user to gain unauthorized access to vaults poses a severe risk to organizational security, as these vaults often contain administrative credentials and sensitive infrastructure data. With a CVSS score of 8.4, this high-severity flaw could lead to complete compromise of managed systems and lateral movement within the network.

Remediation

Immediate Action: Review the official security advisory at the Devolutions portal to identify the specific patched release and apply the update immediately.

Proactive Monitoring: Audit API request logs for unusual patterns, specifically looking for temporary access approvals originating from unauthorized or non-administrative user accounts.

Compensating Controls: Restrict API access for standard users where possible and enforce strict Multi-Factor Authentication (MFA) requirements for all vault access attempts to mitigate the impact of compromised sessions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the direct impact on credential management, this vulnerability represents a significant risk to the integrity of your security infrastructure. Administrators should prioritize identifying all instances of Devolutions Server and applying the vendor-provided patch as soon as it becomes available to prevent unauthorized access to sensitive vaults.

More Devolutions CVEs

Sources

Originally found and disclosed by Gino Boudreau (mononclemich), per the CVE Program record.