Description
Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints.



This issue affects the following versions :

*

Devolutions Server 2026.1.6.0 through 2026.1.11.0


*

Devolutions Server 2025.3.16.0 and earlier
Published: 2026-05-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in Devolutions Server’s PAM module allows an authenticated user who owns a PAM license but lacks additional permissions to craft requests to the PAM API endpoints and retrieve OTP secret keys and recovery codes. The flaw directly exposes authentication credentials that are meant to protect user accounts, thereby compromising confidentiality and authentication integrity. This weakness is identified as a missing authorization issue (CWE‑862).

Affected Systems

Devolutions Server releases 2026.1.6.0 through 2026.1.11.0 and all 2025.3.16.0 releases and earlier are impacted. If a system is running any of those versions or an older 2025.x or 2026.x build before 2026.1.12.0, it is vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1 % shows a low probability of exploitation. Nevertheless, because the vulnerability permits the acquisition of OTP secrets – credentials that could allow an attacker to compromise protected accounts – the potential impact on authentication security remains concerning. The vulnerability is not listed in CISA’s KEV catalog, so current known exploitation activity is not documented.

Generated by OpenCVE AI on May 13, 2026 at 18:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Devolutions Server to a version newer than 2026.1.11.0 that contains the fix for the PAM module authorization error.
  • If an upgrade cannot be performed immediately, limit the permissions of all users with a PAM license to only those required for their role and prohibit them from accessing API endpoints that return OTP secrets or recovery codes.
  • Ensure that any remaining PAM API calls validate user permissions rigorously so that only accounts explicitly authorized to retrieve OTP information can do so.

Generated by OpenCVE AI on May 13, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions devolutions Server
CPEs cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Vendors & Products Devolutions devolutions Server

Wed, 13 May 2026 19:15:00 +0000

Type Values Removed Values Added
Title Missing Authorization in PAM Module Exposes OTP Secrets in Devolutions Server

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 18:15:00 +0000

Type Values Removed Values Added
Title Missing Authorization in PAM Module Exposes OTP Secrets in Devolutions Server

Tue, 12 May 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Tue, 12 May 2026 16:45:00 +0000

Type Values Removed Values Added
Description Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.11.0 * Devolutions Server 2025.3.16.0 and earlier
Weaknesses CWE-862
References

Subscriptions

Devolutions Devolutions Server Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-05-13T16:00:40.920Z

Reserved: 2026-05-12T16:10:27.403Z

Link: CVE-2026-8407

cve-icon Vulnrichment

Updated: 2026-05-13T16:00:38.254Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T17:16:22.043

Modified: 2026-05-26T12:32:46.110

Link: CVE-2026-8407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T19:00:15Z

Weaknesses