CVE-2026-15641

7.1

Devolutions · Server

An improper authorization flaw in Devolutions Server allows authenticated low-privileged users to approve their own pending access requests.

Executive summary

An improper authorization vulnerability in Devolutions Server versions prior to 2026.1.23 and 2026.2.12 allows authenticated low-privileged users to approve their own access requests, leading to unauthorized resource access.

Vulnerability

This is an improper authorization vulnerability (CWE-863) within the access request status endpoint, requiring low-privileged authenticated user access and no user interaction to exploit via direct API calls.

Business impact

A successful exploit permits unauthorized users to elevate their privileges and gain sensitive access by self-approving pending requests, undermining internal security controls and data segregation policies. With a CVSS score of 7.1, this high-severity vulnerability poses a significant risk to organizational confidentiality and integrity by bypassing mandatory management reviews.

Remediation

Immediate Action: Update Devolutions Server to version 2026.1.23 or 2026.2.12, or the latest available vendor release.

Proactive Monitoring: Review audit logs for anomalous self-approval patterns on access requests and monitor low-privileged user account activities.

Compensating Controls: Implement strict network segmentation and monitor API endpoint invocation frequencies for unauthorized direct calls to the access request status module.

Exploitation status

Public Exploit Available: No (false / unknown)

Analyst recommendation

Administrators must treat this high-severity vulnerability with urgency to prevent internal privilege abuse and unauthorized resource access. Apply the vendor updates immediately and audit existing access control approvals to ensure no unauthorized escalations have already occurred.

More Devolutions CVEs

Sources