CVE-2026-15637: High severity Devolutions Devolutions Server 2026.2.11 vulnerability
Published Jul 14, 2026
·Updated
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
Affected Software
4 affected components
Devolutions Devolutions Server 2026.2.11=2026.2.11
Devolutions Devolutions Server 2026.1.22=2026.1.22
Devolutions Devolutions Server<2026.1.23.0
Devolutions Devolutions Server>=2026.2.0.0<2026.2.12.0
Event History
Jul 14, 2026
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-15637?
The severity of CVE-2026-15637 is high with a CVSS score of 7.5.
2
How does CVE-2026-15637 impact users?
CVE-2026-15637 allows an authenticated low-privileged user to disclose private keys of SSH key or certificate PAM credentials.
3
How do I fix CVE-2026-15637?
To fix CVE-2026-15637, update to Devolutions Server version 2026.2.12 or later.
4
What versions of Devolutions Server are affected by CVE-2026-15637?
CVE-2026-15637 affects Devolutions Server versions 2026.2.11 and 2026.1.22.
5
What kind of vulnerability is CVE-2026-15637?
CVE-2026-15637 is an improper authorization vulnerability related to SSH key and certificate retrieval.