Impact
The vulnerability is a permission cache poisoning flaw in Devolutions Server. An authenticated user can manipulate the cache and gain access to entries they should not be able to view, effectively bypassing the server’s ACL enforcement. The impact is direct unauthorized data exposure to legitimate accounts that have not been granted the necessary permissions.
Affected Systems
The flaw affects Devolutions Server versions prior to 2025.3.15. Users running those versions risk having their access controls subverted and their data exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% shows that widespread exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need valid credentials with which to change the permission cache, so the threat remains largely confined to legitimate users with some level of access. Nonetheless, the potential for unauthorized data access makes it prudent to mitigate as soon as possible.
OpenCVE Enrichment