CVE-2026-7325: SSRF
Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM provider service account via authentication relay to an attacker-controlled server.
This issue affects :
Devolutions Server 2026.1.6.0 through 2026.1.16.0 Devolutions Server 2025.3.20.0 and earlier
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7325?
CVE-2026-7325 has a risk rating of 72, indicating a significant security concern.
How do I fix CVE-2026-7325?
To fix CVE-2026-7325, ensure that all Devolutions Server components are updated to the latest version that addresses this vulnerability.
What impact does CVE-2026-7325 have on Devolutions Server?
CVE-2026-7325 allows low-privileged authenticated users to obtain sensitive authentication information through improper authorization.
Who is affected by CVE-2026-7325?
Any organization using the affected version of Devolutions Server is susceptible to CVE-2026-7325.
How can I mitigate risks associated with CVE-2026-7325?
To mitigate risks from CVE-2026-7325, implement strict access controls and monitor user permissions closely within the Devolutions Server environment.