CVE-2026-17568
Devolutions · Server
Improper access control in the Devolutions Server role management endpoint allows authenticated non-administrative users with specific permissions to escalate privileges to administrator via API requests.
Executive summary
An improper access control vulnerability in Devolutions Server allows authenticated users with specific permissions to escalate their privileges to administrator, granting them full control over the application.
Vulnerability
The vulnerability resides in the role membership management endpoint. Authenticated users who hold user-group management permissions can craft malicious API requests to bypass authorization checks and elevate their account status to administrative level.
Business impact
The ability for a standard user to become an administrator poses a critical threat to the security of the Devolutions Server environment. With a CVSS score of 8.8, this could lead to the total compromise of sensitive stored credentials, unauthorized modification of security policies, and complete control over the managed infrastructure.
Remediation
Immediate Action: Update Devolutions Server to version 2026.1.24 or 2026.2.14, depending on the current branch in use.
Proactive Monitoring: Monitor API logs for suspicious requests targeting the role membership management endpoint, particularly those originating from non-administrative accounts.
Compensating Controls: Restrict access to the API and administrative interfaces to trusted IP ranges until the patch can be applied.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Privilege escalation vulnerabilities in identity and access management tools are exceptionally dangerous. Security teams should expedite the deployment of the provided patches to ensure that administrative access remains protected and limited to authorized personnel.