CyberRota
← Ana sayfaya dön

CVE-2026-8407

MEDIUM · CVSS 4.3 EPSS %0.02

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-12T17:16:22.043 · Çekilme zamanı: 2026-06-09T06:00:52.959332+00:00

CyberRota Yorumu

Saldırganın giriş yapmış olması gerekebilir.

CVE
CVE-2026-8407
Severity
MEDIUM
CVSS
4.3
EPSS
%0.02

Orijinal NVD Açıklaması

Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.11.0 * Devolutions Server 2025.3.16.0 and earlier