CVE-2026-9249: Low severity Devolutions Devolutions Server vulnerability
Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request.
This issue affects :
Devolutions Server 2026.1.6.0 through 2026.1.16.0 Devolutions Server 2025.3.20.0 and earlier
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to Devolutions Server management interfaces and the password-change endpoint to trusted networks (firewall rules, VPN, or ACLs). Deploy a WAF or request-filtering rule to block or challenge suspicious/unauthenticated password-change requests.
- Operational
Reset/rotate passwords for Devolutions Server user accounts that may have been impacted and invalidate active sessions/tokens to prevent use of any unauthorized password changes.
- Operational
Prioritize applying official vendor fixes when released; particularly update servers running the affected versions: Devolutions Server 2026.1.6.0 through 2026.1.16.0 and Devolutions Server 2025.3.20.0 and earlier.
- Operational
Enable and monitor logging/alerts for unexpected password-change requests and anomalous account activity on Devolutions Server; investigate and remediate any suspicious events.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9249?
The severity of CVE-2026-9249 is rated at 71, indicating a moderate risk level.
How do I fix CVE-2026-9249?
To fix CVE-2026-9249, upgrade to Devolutions Server version 2026.1.17.0 or later.
What systems are affected by CVE-2026-9249?
CVE-2026-9249 affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0 and all versions of Devolutions Server prior to 2025.3.20.0.
What type of vulnerability is CVE-2026-9249?
CVE-2026-9249 is an unverified password change vulnerability that allows an attacker to modify user passwords without prior verification.
Who can be impacted by CVE-2026-9249?
Any user of Devolutions Server within the affected versions may be vulnerable to unauthorized password changes.