CVE-2026-9248: Low severity Devolutions Devolutions Server vulnerability
Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request.
This issue affects :
Devolutions Server 2026.1.6.0 through 2026.1.16.0 Devolutions Server 2025.3.20.0 and earlier
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the entry duplication feature until a vendor-supplied fix is available to prevent authenticated users with write access from copying documentation and attachments from vaults they should not access.
Devolutions Server entry duplication feature = disabled - Compensating control
Limit and audit write access to vaults so that only trusted accounts have write permissions; if possible, restrict access to the management interface by network ACLs or firewall rules to reduce the risk of exploitation by authenticated users.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9248?
The severity of CVE-2026-9248 is rated at risk level 52.
What does CVE-2026-9248 exploit?
CVE-2026-9248 exploits an authorization bypass in the entry duplication feature of Devolutions Server.
Who is affected by CVE-2026-9248?
Authenticated users with write access to any vault in Devolutions Server are affected by CVE-2026-9248.
How can CVE-2026-9248 be mitigated?
Mitigation of CVE-2026-9248 involves restricting write access to unauthorized users in Devolutions Server.
What versions of Devolutions Server are affected by CVE-2026-9248?
CVE-2026-9248 affects Devolutions Server version 2026.1.6.0 and potentially earlier versions.