CVE-2026-9522: Medium severity Devolutions Devolutions Server vulnerability
Published Jun 2, 2026
·Updated
Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.
Affected Software
2 affected components
Devolutions Devolutions Server<=2026.1.19
Devolutions Devolutions Server<2026.1.20.0
Event History
Jun 2, 2026
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 30, 58405
Event
via FIRST·07:28 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-9522?
The severity of CVE-2026-9522 is rated as medium with a CVSS score of 5.4.
2
How does CVE-2026-9522 impact Devolutions Server?
CVE-2026-9522 allows authenticated users without administrative privileges to delete network discovery scan configurations.
3
Who is affected by CVE-2026-9522?
Users of Devolutions Server versions 2026.1.19 and earlier are affected by CVE-2026-9522.
4
How do I fix CVE-2026-9522?
To mitigate CVE-2026-9522, upgrade to Devolutions Server version 2026.1.20 or later.
5
What does CVE-2026-9522 describe?
CVE-2026-9522 describes an improper access control vulnerability in the PAM account discovery feature.