Vulnerabilidades em Devolutions

176 resultados
Análise Vexday

Com 153 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o portfólio de vulnerabilidades da Devolutions apresenta atividade recente relevante que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, e nenhuma PoC pública foi identificada, o que reduz o risco imediato de exploração em massa. No entanto, a presença de 10 falhas críticas e o predomínio de CWE-284 (controle de acesso inadequado) indicam uma superfície de ataque estruturalmente sensível, especialmente em ambientes com gestão privilegiada de acessos remotos. A CVE mais perigosa atualmente rastreada, CVE-2021-42098, registra EPSS de 0,016, sugerindo probabilidade de exploração ainda baixa, mas equipes de segurança devem monitorar esse indicador dado o volume de novas entradas recentes.

CVE-2026-6706MEDIUMImproper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation coEPSS 0.2%CVE-2026-8407MEDIUMMissing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions EPSS 0.2%CVE-2026-10544MEDIUMImproper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authentEPSS 0.2%CVE-2026-9251MEDIUMMissing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass tEPSS 0.2%CVE-2026-4925MEDIUMImproper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restricEPSS 0.2%CVE-2026-9248LOWAuthorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to cEPSS 0.2%CVE-2026-9249LOWUnverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a craEPSS 0.2%CVE-2026-9590MEDIUMImproper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user withEPSS 0.2%CVE-2023-2257MEDIUMAuthentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attEPSS 0.2%CVE-2026-3638MEDIUMImproper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authentEPSS 0.2%CVE-2026-0618MEDIUMCross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13.EPSS 0.2%CVE-2025-2528LOWImproper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use EPSS 0.2%CVE-2026-4829MEDIUMImproper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user tEPSS 0.2%CVE-2023-7047 Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop ManagerEPSS 0.2%CVE-2026-4989MEDIUMImproper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform seEPSS 0.2%CVE-2026-5146MEDIUMImproper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or deletEPSS 0.2%CVE-2026-17569MEDIUMImproper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry EPSS 0.2%CVE-2022-3182Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackersEPSS 0.2%CVE-2026-17570MEDIUMImproper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose EPSS 0.2%CVE-2026-3277MEDIUMThe OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext iEPSS 0.2%