PT-2025-31415 · Devolutions · Devolutions Server

Published

2025-07-30

·

Updated

2025-07-30

·

CVE-2025-8353

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions prior to 2025.2.4.0
Description A UI synchronization issue exists in the Just-in-Time (JIT) access request approval interface. This issue allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.
Recommendations Update Devolutions Server to version 2025.2.4.0 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-8353

Affected Products

Devolutions Server