CVE-2026-9223: Medium severity Devolutions Devolutions Server vulnerability
Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the vault import feature until a patched version is available or the issue is otherwise remediated.
Devolutions Server vault_import_enabled = false - Compensating control
Restrict access to the vault import endpoint and import functionality to trusted administrative users only (for example via network ACLs, WAF rules, or RBAC) to prevent low-privileged authenticated users from invoking import operations.
- Operational
Audit existing vaults and logs for any vaults created via the import functionality by low-privileged accounts; remove or quarantine unauthorized vaults and remediate any identified misuse.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9223?
CVE-2026-9223 has a risk score of 47, indicating a moderate severity level.
How do I fix CVE-2026-9223?
To remediate CVE-2026-9223, upgrade to Devolutions Server version 2026.1.16.1 or later.
Who is affected by CVE-2026-9223?
CVE-2026-9223 affects low-privileged authenticated users of Devolutions Server versions 2026.1.16.0 and earlier.
What type of vulnerability is CVE-2026-9223?
CVE-2026-9223 is a missing authorization vulnerability that allows unauthorized vault creation.
When was CVE-2026-9223 published?
CVE-2026-9223 was published on May 22, 2026.