SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-15637

HIGH · CVSS 7.5 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Improper authorization in the PAM SSH key and certificate retrieval endpoints of Devolutions Server allows authenticated low-privileged users to access and disclose private keys associated with SSH keys or PAM credentials. This vulnerability poses a significant risk as it can lead to unauthorized access to sensitive systems and data. Organizations using affected versions of Devolutions Server should prioritize remediation to mitigate potential exploitation.

CVE
CVE-2026-15637
Severity
HIGH
CVSS
7.5
EPSS
0.19%

Original NVD Description

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.

Related CVEs

Other vulnerabilities affecting the same vendor(s)