CVE-2026-17568
N/A
N/A
Summary
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request.
This issue affects :
- Devolutions Server 2026.2.4.0 through 2026.2.12.0
- Devolutions Server 2026.1.23.0 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Devolutions | Server | 0 < 2026.1.24 | affected |
| Devolutions | Server | 2026.2.4.0 < 2026.2.14 | affected |
Weaknesses
- CWE-863: CWE-863 Incorrect Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.