Improper Authorization in Devolutions Server Affects User Data Security
CVE-2026-7325
7.1HIGH
What is CVE-2026-7325?
An improper authorization vulnerability exists in the Active Directory browsing feature of Devolutions Server. This flaw allows low-privileged authenticated users to exploit the system, enabling them to obtain sensitive authentication materials associated with a stored PAM provider service account. By executing an authentication relay to a malicious server, attackers can potentially compromise user credentials and access secured information, increasing the risk of data breaches and unauthorized access.
Affected Version(s)
Server 2026.1.6.0 <= 2026.1.16.0
Server 0 <= 2025.3.20.0
