CVE-2026-12755: Input Validation
Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12755?
The severity of CVE-2026-12755 is classified as low.
How do I fix CVE-2026-12755?
To fix CVE-2026-12755, ensure the software is updated to Devolutions Server version 2026.2.8.0 or later.
What type of vulnerability is CVE-2026-12755?
CVE-2026-12755 is an improper input validation vulnerability.
Who is affected by CVE-2026-12755?
Authenticated users with the UserGroupsView permission in Devolutions Server are affected by CVE-2026-12755.
What are the risks associated with CVE-2026-12755?
CVE-2026-12755 allows potential exposure of PAM provider credentials to an attacker-controlled host.