Improper Rule Enforcement in PAM Active Directory Provider of Devolutions Server
CVE-2026-93330
4.3MEDIUM
What is CVE-2026-93330?
An improper rule enforcement issue in the PAM Active Directory provider of Devolutions Server 2026.3.5 allows users with PAM edit permissions to circumvent the established rules in the Devolutions Gateway host ruleset. This flaw can potentially enable unauthorized actions and jeopardize the integrity of systems relying on proper PAM configurations.
Affected Version(s)
Server 0 < 2026.3.7.0
