CRITICAL🇵🇱 Wersja polska

CVE-2025-11957

CVSS 9.0v4.0pub. 2025-10-22upd. 2025-11-25

Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.

🤖 AI Analysis
How it works

The temporary access workflow mechanism does not properly verify whether the user submitting the approval request has the appropriate permissions to accept it (CWE-639: Insecure Direct Object Reference / Improper Authorization). An attacker with a regular user account can send crafted API requests that bypass authorization controls and allow approval of their own or another user's temporary access request. No interaction from an administrator is required, nor is elevated privilege necessary – only a valid account in the system is sufficient.

Impact

An attacker can gain unauthorized access to vaults and entries managed by Devolutions Server, including potentially stored passwords, keys, and other sensitive authentication data. It is also possible to approve requests from other users, which leads to a violation of the integrity of the access control process throughout the organization.

Mitigation & patch

Devolutions Server must be updated to a version newer than 2025.2.12.0 according to the manufacturer's recommendations described in advisory DEVO-2025-0015 available at https://devolutions.net/security/advisories/DEVO-2025-0015/

Who is affected

Devolutions Server version 2025.2.12.0 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Devolutions Server

    APP
    Devolutions
    < 2025.2.14.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-3130CRITICAL9.8PL ✓same product

Devolutions Server: nieuprawnione usuwanie kont PAM przez bulk deletion

CVE-2026-3224CRITICAL9.8PL ✓same product

Authentication bypass w Devolutions Server przez sfałszowany JWT (Entra ID)

CVE-2026-3204CRITICAL9.8PL ✓same product

Devolutions Server — spoofing komunikatu błędu przez nieprawidłową walidację danych wejściowych

CVE-2026-0610CRITICAL9.8PL ✓same product

SQL Injection w module remote-sessions Devolutions Server

CVE-2025-6523CRITICAL9.5PL ✓same product

Devolutions Server – pominięcie uwierzytelnienia przez brute force kodów awaryjnych