CVE-2026-8407: Medium severity Devolutions Devolutions Server vulnerability
Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints.
This issue affects the following versions :
Devolutions Server 2026.1.6.0 through 2026.1.11.0
Devolutions Server 2025.3.16.0 and earlier
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8407?
CVE-2026-8407 has a medium severity level due to the potential exposure of OTP secret keys and recovery codes.
How do I fix CVE-2026-8407?
To mitigate CVE-2026-8407, ensure that users with PAM licenses have appropriate permissions and update to a patched version of Devolutions Server.
Who is affected by CVE-2026-8407?
CVE-2026-8407 affects authenticated users of the Devolutions Server with PAM licenses lacking adequate permissions across certain versions.
What systems are vulnerable to CVE-2026-8407?
Devolutions Server versions between 2025.3.16.0 and 2026.1.11.0 are vulnerable to CVE-2026-8407.
What can attackers do with CVE-2026-8407?
Attackers can exploit CVE-2026-8407 to craft requests that reveal OTP secret keys and recovery codes from the PAM API.