CVE-2026-17568

EUVD-2026-49377
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request.

This issue affects :

  *  Devolutions Server 2026.2.4.0 through 2026.2.12.0
  *  Devolutions Server 2026.1.23.0 and earlier
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 14.06%
Affected Products (NVD)
VendorProductVersion
devolutionsdevolutions_server
𝑥
< 2026.1.24.0
devolutionsdevolutions_server
2026.2.4.0 ≤
𝑥
< 2026.2.14.0
𝑥
= Vulnerable software versions