Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN787 _____________________________________________________________________ DATE : 28/07/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Devolutions Server versions prior to 2026.1.24.0, 2026.2.14.0. ===================================================================== https://devolutions.net/security/advisories/DEVO-2026-0026/ _____________________________________________________________________ DEVO-2026-0026 Devolutions Server is affected by multiple vulnerabilities. Affected Products Devolutions Server 2026.2.4.0 through 2026.2.12.0 2026.1.23.0 and earlier Change Log Initial publication - 2026-07-27 Improper access control in role membership management leads to privilege escalation 7.4 High - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Improper access control in the role membership management endpoint in Devolutions Server 2026.2.12.0 and earlier allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. CVE(s) CVE-2026-17568 Remediation and Workarounds Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher. Sensitive token exposure in NetBox synchronizer 6.3 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N Improper access control in the NetBox synchronizer in Devolutions Server 2026.2.12.0 and earlier allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. CVE(s) CVE-2026-17569 Remediation and Workarounds Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher. Improper access control in PAM password history endpoints 4.3 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Improper access control in the PAM password history endpoints in Devolutions Server 2026.2.12.0 and earlier allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. CVE(s) CVE-2026-17570 Remediation and Workarounds Upgrade to Devolutions Server 2026.1.24.0 or 2026.2.14.0 or higher. Credits dorjoo ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================