Description
Improper authorization in the PAM SSH key and certificate retrieval
endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an
authenticated low-privileged user to disclose the private key of an SSH
key or certificate PAM credential via a direct object reference to the
credential identifier.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Devolutions Server 2026.2.11 and 2026.1.22 allows authenticated users with low privileges to retrieve the private key of an SSH or certificate PAM credential through a direct object reference. This improper authorization results in the disclosure of sensitive cryptographic material, exposing the user to credential compromise. The flaw is categorized as CWE‑639, indicating an authorization bypass that leads to confidentiality loss.

Affected Systems

Affected are Devolutions Server versions 2026.2.11 and 2026.1.22. Any installation of these releases that has the PAM SSH key or certificate retrieval endpoints enabled is vulnerable. The product is Devolutions Server, a privileged access management platform.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, the EPSS score indicates exploitation is unlikely (<1%) and it is currently not in the CISA KEV catalog. The exploit requires an authenticated low‑privileged account and knowledge or enumeration of the credential identifier; therefore the attack surface is limited to users with legitimate access. The likely attack vector is via an authenticated request to the credential retrieval endpoint, using a valid credential ID, as inferred from the description. Once a private key is disclosed, lateral movement and compromise of other systems become possible.

Generated by OpenCVE AI on August 1, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Devolutions Server to the latest patched release that removes the authorization check.
  • Restrict access to the credential retrieval endpoints to administrators only and enforce strict role‑based access control as an interim measure.
  • Apply network segmentation or firewall rules to limit where authenticated low‑privileged users can reach the vulnerable endpoints.
  • Review and tighten least privilege policies to eliminate unnecessary low‑privileged accounts that have access to the PAM system.

Generated by OpenCVE AI on August 1, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Devolutions Server PAM Credential Disclosure via Direct Object Reference

Wed, 29 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Disclosure of Private SSH Keys

Sat, 25 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Disclosure of Private SSH Keys

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Low-Privileged User to Retrieve Private SSH Key in Devolutions Server

Thu, 16 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Low-Privileged User to Retrieve Private SSH Key in Devolutions Server

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
Weaknesses CWE-639
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-15T14:40:46.594Z

Reserved: 2026-07-13T18:17:50.907Z

Link: CVE-2026-15637

cve-icon Vulnrichment

Updated: 2026-07-15T14:40:24.485Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key