Impact
The vulnerability in Devolutions Server 2026.2.11 and 2026.1.22 allows authenticated users with low privileges to retrieve the private key of an SSH or certificate PAM credential through a direct object reference. This improper authorization results in the disclosure of sensitive cryptographic material, exposing the user to credential compromise. The flaw is categorized as CWE‑639, indicating an authorization bypass that leads to confidentiality loss.
Affected Systems
Affected are Devolutions Server versions 2026.2.11 and 2026.1.22. Any installation of these releases that has the PAM SSH key or certificate retrieval endpoints enabled is vulnerable. The product is Devolutions Server, a privileged access management platform.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, the EPSS score indicates exploitation is unlikely (<1%) and it is currently not in the CISA KEV catalog. The exploit requires an authenticated low‑privileged account and knowledge or enumeration of the credential identifier; therefore the attack surface is limited to users with legitimate access. The likely attack vector is via an authenticated request to the credential retrieval endpoint, using a valid credential ID, as inferred from the description. Once a private key is disclosed, lateral movement and compromise of other systems become possible.
OpenCVE Enrichment