CVE-2026-9247: Low severity Devolutions Devolutions Server vulnerability

Published May 22, 2026
·
Updated

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request.

This issue affects :

Devolutions Server 2026.1.6.0 through 2026.1.16.0 Devolutions Server 2025.3.20.0 and earlier

Affected Software

3 affected components
Devolutions Devolutions Server>=2026.1.6.0<=2026.1.16.0, <=2025.3.20.0
Devolutions Devolutions Server<2025.3.22.0
Devolutions Devolutions Server>=2026.1.6.0<2026.1.19.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    If possible, disable the entry export feature until a vendor fix is available; if disabling is not feasible, limit its use to a small set of administrators.

    Devolutions Server entry_export = disabled or limited
  2. Configuration

    Remove export permissions from users who do not require them and grant export permission only to a minimal set of trusted administrator accounts.

    Devolutions Server export_permissions = restricted to trusted administrators
  3. Compensating control

    Monitor and audit export activity for sealed entries and implement alerts for any export attempts or completed exports of sealed entries, since unseal notifications may not be triggered.

  4. Operational

    Investigate recent export events for sealed entries, notify administrators of any confirmed exports, and perform incident response as appropriate (review exposure, notify stakeholders).

Event History

May 22, 2026
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Jul 3, 58550
Event
via FIRST·10:56 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9247?

CVE-2026-9247 has a risk score of 37 indicating a moderate level of severity.

2

How do I fix CVE-2026-9247?

To mitigate CVE-2026-9247, ensure you update to the latest version of Devolutions Server where the logging issue is addressed.

3

Who is affected by CVE-2026-9247?

CVE-2026-9247 affects authenticated users with export permissions on Devolutions Server versions 2026.1.6.0 and earlier.

4

What impact does CVE-2026-9247 have on security?

CVE-2026-9247 allows users to export a sealed entry without notifying administrators, which compromises accountability.

5

When was CVE-2026-9247 published?

CVE-2026-9247 was published on May 22, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203