SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-17568

HIGH · CVSS 8.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Improper access control in the role membership management endpoint of Devolutions Server enables authenticated non-administrative users with specific permissions to escalate their privileges to administrator level through a crafted API request. This vulnerability poses a significant risk as it allows unauthorized access to sensitive administrative functions, potentially compromising the integrity and security of the server. Organizations using affected versions of Devolutions Server should prioritize immediate remediation to mitigate the risk of privilege escalation attacks.

CVE
CVE-2026-17568
Severity
HIGH
CVSS
8.8
EPSS
0.23%

Original NVD Description

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)