Impact
Improper authorization in Devolutions Server 2026.2.11 and 2026.1.22 allows any authenticated low‑privilege user to self‑approve an access request by calling the request status endpoint directly. The flaw bypasses the required review process and grants the user access that should be restricted, potentially exposing sensitive resources and violating least‑privilege principles.
Affected Systems
Devolutions Server 2026.2.11 and 2026.1.22 are affected; the vulnerability resides in the access request status endpoint responsible for approving pending requests.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact, while an EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is a direct API call to the request status endpoint by an authenticated user with a low‑privilege role; no elevated privileges or external network exposure are required. The flaw enables an attacker to obtain privileged or unintended access by approving their own requests, undermining the intended access control workflow.
OpenCVE Enrichment