CVE-2026-9248: Low severity Devolutions Devolutions Server vulnerability

Published May 22, 2026
·
Updated

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request.

This issue affects :

Devolutions Server 2026.1.6.0 through 2026.1.16.0 Devolutions Server 2025.3.20.0 and earlier

Affected Software

3 affected components
Devolutions Devolutions Server>=2026.1.6.0<=2026.1.16.0, <=2025.3.20.0
Devolutions Devolutions Server<2025.3.22.0
Devolutions Devolutions Server>=2026.1.6.0<2026.1.19.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable the entry duplication feature until a vendor-supplied fix is available to prevent authenticated users with write access from copying documentation and attachments from vaults they should not access.

    Devolutions Server entry duplication feature = disabled
  2. Compensating control

    Limit and audit write access to vaults so that only trusted accounts have write permissions; if possible, restrict access to the management interface by network ACLs or firewall rules to reduce the risk of exploitation by authenticated users.

Event History

May 22, 2026
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Jul 3, 58550
Event
via FIRST·09:10 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9248?

The severity of CVE-2026-9248 is rated at risk level 52.

2

What does CVE-2026-9248 exploit?

CVE-2026-9248 exploits an authorization bypass in the entry duplication feature of Devolutions Server.

3

Who is affected by CVE-2026-9248?

Authenticated users with write access to any vault in Devolutions Server are affected by CVE-2026-9248.

4

How can CVE-2026-9248 be mitigated?

Mitigation of CVE-2026-9248 involves restricting write access to unauthorized users in Devolutions Server.

5

What versions of Devolutions Server are affected by CVE-2026-9248?

CVE-2026-9248 affects Devolutions Server version 2026.1.6.0 and potentially earlier versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203