Improper Access Control in Devolutions Server Affects User Permissions
CVE-2025-0691
5MEDIUM
What is CVE-2025-0691?
In Devolutions Server versions prior to 2025.1.10.0, an improper access control flaw exists in the permissions component. This vulnerability enables an authenticated user to circumvent the 'Edit permission' controls through manipulation of client-side validation processes, potentially leading to unauthorized access to sensitive actions within the server.
Affected Version(s)
Server 0 <= 2025.1.10.0