CVE-2026-17568: High severity Devolutions Devolutions Server vulnerability
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request.
This issue affects :
Devolutions Server 2026.2.4.0 through 2026.2.12.0 Devolutions Server 2026.1.23.0 and earlier
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17568?
The severity of CVE-2026-17568 is rated as high with a CVSS score of 8.8.
How do I fix CVE-2026-17568?
To fix CVE-2026-17568, update to the latest version of Devolutions Server that addresses this improper access control vulnerability.
Who is affected by CVE-2026-17568?
CVE-2026-17568 affects authenticated non-administrative users with user-group membership management permission in Devolutions Server.
What is the impact of CVE-2026-17568?
The impact of CVE-2026-17568 is that it allows an unauthorized user to escalate privileges to administrator status through crafted API requests.
What does CVE-2026-17568 exploit?
CVE-2026-17568 exploits improper access control in the role membership management endpoint in Devolutions Server.