CVE-2026-9247: Low severity Devolutions Devolutions Server vulnerability
Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request.
This issue affects :
Devolutions Server 2026.1.6.0 through 2026.1.16.0 Devolutions Server 2025.3.20.0 and earlier
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
If possible, disable the entry export feature until a vendor fix is available; if disabling is not feasible, limit its use to a small set of administrators.
Devolutions Server entry_export = disabled or limited - Configuration
Remove export permissions from users who do not require them and grant export permission only to a minimal set of trusted administrator accounts.
Devolutions Server export_permissions = restricted to trusted administrators - Compensating control
Monitor and audit export activity for sealed entries and implement alerts for any export attempts or completed exports of sealed entries, since unseal notifications may not be triggered.
- Operational
Investigate recent export events for sealed entries, notify administrators of any confirmed exports, and perform incident response as appropriate (review exposure, notify stakeholders).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9247?
CVE-2026-9247 has a risk score of 37 indicating a moderate level of severity.
How do I fix CVE-2026-9247?
To mitigate CVE-2026-9247, ensure you update to the latest version of Devolutions Server where the logging issue is addressed.
Who is affected by CVE-2026-9247?
CVE-2026-9247 affects authenticated users with export permissions on Devolutions Server versions 2026.1.6.0 and earlier.
What impact does CVE-2026-9247 have on security?
CVE-2026-9247 allows users to export a sealed entry without notifying administrators, which compromises accountability.
When was CVE-2026-9247 published?
CVE-2026-9247 was published on May 22, 2026.