PT-2025-23929 · Devolutions · Devolutions Server

Published

2025-06-05

·

Updated

2025-07-02

·

CVE-2025-0691

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.1.10.0 and earlier
Description The issue is related to improper access control in the permissions component, allowing an authenticated user to bypass the "Edit permission" permission. This is achieved by bypassing the client-side validation.
Recommendations For Devolutions Server versions 2025.1.10.0 and earlier, consider restricting access to the permissions component to prevent authenticated users from bypassing the "Edit permission" permission until a fix is available. As a temporary workaround, ensure that server-side validation is enforced to prevent unauthorized edits.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-0691

Affected Products

Devolutions Server