CVE-2025-6741

7.7

Devolutions · Devolutions Server

An improper access control vulnerability in the secure message component of Devolutions Server allows authenticated users to access unauthorized entries via attachment features.

Executive summary

A vulnerability in Devolutions Server allows authenticated users to perform unauthorized data extraction via the secure message component, posing a significant risk to sensitive information.

Vulnerability

This is an improper access control flaw (CWE-284) located within the secure message attachment feature, requiring the attacker to be an authenticated user to successfully trigger the unauthorized data theft.

Business impact

The ability for an authenticated user to bypass access controls and steal unauthorized entries can lead to severe data breaches, particularly in centralized password and credential management environments. Given the CVSS score of 7.7, this is classified as a High-severity risk, as it undermines the confidentiality of stored secrets and could lead to broad unauthorized access across the organization.

Remediation

Immediate Action: Administrators should monitor the vendor security advisory page for the release of a patched version of Devolutions Server and apply it immediately upon availability.

Proactive Monitoring: Security teams should review audit logs for unusual patterns of access regarding secure message attachments or unauthorized attempts to retrieve sensitive entries.

Compensating Controls: Restrict access to the secure message component to only those users who strictly require it, and ensure that internal network segmentation limits the blast radius of any potentially compromised accounts.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the High severity of this vulnerability, organizations should prioritize the identification of affected Devolutions Server instances. Once the vendor provides a patch, it must be deployed immediately to prevent internal users from exploiting this access control weakness to gain unauthorized access to sensitive data repositories.

More Devolutions CVEs

Sources

Originally found and disclosed by Gino Boudreau (mononclemich), per the CVE Program record.