CVE-2025-6741
7.7Devolutions · Devolutions Server
An improper access control vulnerability in the secure message component of Devolutions Server allows authenticated users to access unauthorized entries via attachment features.
Executive summary
A vulnerability in Devolutions Server allows authenticated users to perform unauthorized data extraction via the secure message component, posing a significant risk to sensitive information.
Vulnerability
This is an improper access control flaw (CWE-284) located within the secure message attachment feature, requiring the attacker to be an authenticated user to successfully trigger the unauthorized data theft.
Business impact
The ability for an authenticated user to bypass access controls and steal unauthorized entries can lead to severe data breaches, particularly in centralized password and credential management environments. Given the CVSS score of 7.7, this is classified as a High-severity risk, as it undermines the confidentiality of stored secrets and could lead to broad unauthorized access across the organization.
Remediation
Immediate Action: Administrators should monitor the vendor security advisory page for the release of a patched version of Devolutions Server and apply it immediately upon availability.
Proactive Monitoring: Security teams should review audit logs for unusual patterns of access regarding secure message attachments or unauthorized attempts to retrieve sensitive entries.
Compensating Controls: Restrict access to the secure message component to only those users who strictly require it, and ensure that internal network segmentation limits the blast radius of any potentially compromised accounts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the High severity of this vulnerability, organizations should prioritize the identification of affected Devolutions Server instances. Once the vendor provides a patch, it must be deployed immediately to prevent internal users from exploiting this access control weakness to gain unauthorized access to sensitive data repositories.
More Devolutions CVEs
Sources
Originally found and disclosed by Gino Boudreau (mononclemich), per the CVE Program record.