CVE-2026-11890: Medium severity Devolutions Devolutions Server vulnerability
Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Devolutions Serverto a version that resolves this vulnerability.Fixed in 2026.2.5 - Upgrade
Upgrade
Devolutions Serverto a version that resolves this vulnerability.Fixed in 2026.1.21
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11890?
CVE-2026-11890 has a medium severity score of 4.3 based on the CVSS v3.1 metrics.
How do I fix CVE-2026-11890?
To fix CVE-2026-11890, upgrade to the latest version of Devolutions Server where the vulnerability has been addressed.
What type of vulnerability is CVE-2026-11890?
CVE-2026-11890 is an improper access control vulnerability affecting Devolutions Server.
Who is affected by CVE-2026-11890?
Authenticated users of Devolutions Server versions 2026.2.5 and 2026.1.21 are affected by CVE-2026-11890.
What can an attacker do with CVE-2026-11890?
An attacker could retrieve sensitive account discovery scan results due to improper access control in the affected versions.