Description
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
Published: 2026-07-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authorization in Devolutions Server 2026.2.11 and 2026.1.22 allows any authenticated low‑privilege user to self‑approve an access request by calling the request status endpoint directly. The flaw bypasses the required review process and grants the user access that should be restricted, potentially exposing sensitive resources and violating least‑privilege principles.

Affected Systems

Devolutions Server 2026.2.11 and 2026.1.22 are affected; the vulnerability resides in the access request status endpoint responsible for approving pending requests.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, while an EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is a direct API call to the request status endpoint by an authenticated user with a low‑privilege role; no elevated privileges or external network exposure are required. The flaw enables an attacker to obtain privileged or unintended access by approving their own requests, undermining the intended access control workflow.

Generated by OpenCVE AI on August 1, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑issued update that fixes the authorization flaw.
  • Configure role‑based access to ensure that only users with designated approver roles can invoke the request status endpoint.
  • Enable and regularly review audit logging for all access request approvals to detect and deter unauthorized self‑approvals.

Generated by OpenCVE AI on August 1, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Devolutions Server Access Request Endpoint

Sat, 25 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allowing Self-Approval of Access Requests in Devolutions Server 2026

Wed, 22 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allowing Self-Approval of Access Requests in Devolutions Server 2026

Fri, 17 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged User Can Unilaterally Approve Access Requests

Thu, 16 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged User Can Unilaterally Approve Access Requests

Wed, 15 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
Weaknesses CWE-863
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-15T14:41:44.756Z

Reserved: 2026-07-13T18:21:03.185Z

Link: CVE-2026-15641

cve-icon Vulnrichment

Updated: 2026-07-15T14:41:33.609Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:30:03Z

Weaknesses