Impact
A missing authorization check in Devolutions Server’s PAM module allows an authenticated user who owns a PAM license but lacks additional permissions to craft requests to the PAM API endpoints and retrieve OTP secret keys and recovery codes. The flaw directly exposes authentication credentials that are meant to protect user accounts, thereby compromising confidentiality and authentication integrity. This weakness is identified as a missing authorization issue (CWE‑862).
Affected Systems
Devolutions Server releases 2026.1.6.0 through 2026.1.11.0 and all 2025.3.16.0 releases and earlier are impacted. If a system is running any of those versions or an older 2025.x or 2026.x build before 2026.1.12.0, it is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1 % shows a low probability of exploitation. Nevertheless, because the vulnerability permits the acquisition of OTP secrets – credentials that could allow an attacker to compromise protected accounts – the potential impact on authentication security remains concerning. The vulnerability is not listed in CISA’s KEV catalog, so current known exploitation activity is not documented.
OpenCVE Enrichment