CVE-2025-6741: High severity Devolutions Server vulnerability
Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure message entry attachment feature
This issue affects the following versions :
Devolutions Server 2025.2.2.0 through 2025.2.4.0 Devolutions Server 2025.1.11.0 and earlier
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6741?
CVE-2025-6741 has a high severity rating due to improper access control that can lead to unauthorized information disclosure.
How do I fix CVE-2025-6741?
To fix CVE-2025-6741, update to Devolutions Server version 2025.2.4.0 or later, where the vulnerability is addressed.
Who is affected by CVE-2025-6741?
CVE-2025-6741 affects authenticated users of Devolutions Server versions 2025.2.2.0 to 2025.2.4.0 and earlier versions.
What does CVE-2025-6741 exploit?
CVE-2025-6741 exploits a flaw in the secure message component allowing unauthorized access to secure message entry attachments.
When was CVE-2025-6741 disclosed?
CVE-2025-6741 was disclosed in 2025, as part of ongoing security advisories by Devolutions.