CyberRota Analysis
AI-GeneratedImproper access control in the role membership management endpoint of Devolutions Server enables authenticated non-administrative users with specific permissions to escalate their privileges to administrator level through a crafted API request. This vulnerability poses a significant risk as it allows unauthorized access to sensitive administrative functions, potentially compromising the integrity and security of the server. Organizations using affected versions of Devolutions Server should prioritize immediate remediation to mitigate the risk of privilege escalation attacks.
Original NVD Description
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)