Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.
The temporary access workflow mechanism does not properly verify whether the user submitting the approval request has the appropriate permissions to accept it (CWE-639: Insecure Direct Object Reference / Improper Authorization). An attacker with a regular user account can send crafted API requests that bypass authorization controls and allow approval of their own or another user's temporary access request. No interaction from an administrator is required, nor is elevated privilege necessary – only a valid account in the system is sufficient.
An attacker can gain unauthorized access to vaults and entries managed by Devolutions Server, including potentially stored passwords, keys, and other sensitive authentication data. It is also possible to approve requests from other users, which leads to a violation of the integrity of the access control process throughout the organization.
Devolutions Server must be updated to a version newer than 2025.2.12.0 according to the manufacturer's recommendations described in advisory DEVO-2025-0015 available at https://devolutions.net/security/advisories/DEVO-2025-0015/
Devolutions Server version 2025.2.12.0 and earlier
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDevolutions Server
APPDevolutions< 2025.2.14.0
Related vulnerabilities
Devolutions Server: nieuprawnione usuwanie kont PAM przez bulk deletion
Authentication bypass w Devolutions Server przez sfałszowany JWT (Entra ID)
Devolutions Server — spoofing komunikatu błędu przez nieprawidłową walidację danych wejściowych
SQL Injection w module remote-sessions Devolutions Server
Devolutions Server – pominięcie uwierzytelnienia przez brute force kodów awaryjnych