CVE-2025-11957
BaseFortify
Publication date: 2025-10-22
Last updated on: 2025-11-25
Assigner: Devolutions Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| devolutions | devolutions_server | From 2022.3.1.0 (inc) to 2022.3.10.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an improper authorization issue in the temporary access workflow of Devolutions Server version 2025.2.12.0 and earlier. It allows an authenticated basic user to self-approve or approve temporary access requests of other users by sending crafted API requests, thereby gaining unauthorized access to vaults and entries.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to sensitive vaults and entries by users who should not have such permissions. This can result in exposure or misuse of confidential information stored within the Devolutions Server.