CyberRota Analysis
AI-GeneratedImproper authorization in the PAM SSH key and certificate retrieval endpoints of Devolutions Server allows authenticated low-privileged users to access and disclose private keys associated with SSH keys or PAM credentials. This vulnerability poses a significant risk as it can lead to unauthorized access to sensitive systems and data. Organizations using affected versions of Devolutions Server should prioritize remediation to mitigate potential exploitation.
Original NVD Description
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
Related CVEs
Other vulnerabilities affecting the same vendor(s)