Vulnerabilidades en Devolutions

176 resultados
Análisis Vexday

Com 153 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o portfólio de vulnerabilidades da Devolutions apresenta atividade recente relevante que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, e nenhuma PoC pública foi identificada, o que reduz o risco imediato de exploração em massa. No entanto, a presença de 10 falhas críticas e o predomínio de CWE-284 (controle de acesso inadequado) indicam uma superfície de ataque estruturalmente sensível, especialmente em ambientes com gestão privilegiada de acessos remotos. A CVE mais perigosa atualmente rastreada, CVE-2021-42098, registra EPSS de 0,016, sugerindo probabilidade de exploração ainda baixa, mas equipes de segurança devem monitorar esse indicador dado o volume de novas entradas recentes.

CVE-2026-11890MEDIUMImproper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieveEPSS 0.2%CVE-2024-11621HIGHMissing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modifEPSS 0.2%CVE-2026-17568HIGHImproper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holEPSS 0.2%CVE-2026-9245MEDIUMImproper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to reEPSS 0.2%CVE-2023-0463HIGHThe force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022EPSS 0.2%CVE-2024-1900MEDIUMImproper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticatEPSS 0.2%CVE-2026-16798MEDIUMInsertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allowsEPSS 0.2%CVE-2026-4927MEDIUMExposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain otheEPSS 0.2%CVE-2026-1768MEDIUMA permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issEPSS 0.2%CVE-2026-8694MEDIUMImproper access control on the API documentation endpoint in PowerShell UniversalEPSS 0.2%CVE-2026-9247LOWInsufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealEPSS 0.2%CVE-2026-1007HIGHIncorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issueEPSS 0.2%CVE-2026-9223MEDIUMMissing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user EPSS 0.2%CVE-2026-9224MEDIUMMissing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify theirEPSS 0.2%CVE-2026-9246MEDIUMImproper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault reaEPSS 0.2%CVE-2026-90969MEDIUMImproper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking EPSS 0.2%CVE-2026-90971MEDIUMServer-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privilegedEPSS 0.2%CVE-2026-15058LOWImproper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to dEPSS 0.2%CVE-2024-1898LOWImproper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notEPSS 0.2%CVE-2026-0747LOWExposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025EPSS 0.2%