Improper Access Control in Devolutions Server Affects User Permissions
CVE-2025-0691

5MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 June 2025

What is CVE-2025-0691?

In Devolutions Server versions prior to 2025.1.10.0, an improper access control flaw exists in the permissions component. This vulnerability enables an authenticated user to circumvent the 'Edit permission' controls through manipulation of client-side validation processes, potentially leading to unauthorized access to sensitive actions within the server.

Affected Version(s)

Server 0 <= 2025.1.10.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-0691 : Improper Access Control in Devolutions Server Affects User Permissions