CVE-2026-11890
Awaiting Analysis
Awaiting Analysis - Queue
Improper Access Control in Devolutions Server
Publication date: 2026-06-16
Last updated on: 2026-06-16
Assigner: Devolutions Inc.
Description
Description
Improper access control in PAM account discovery results in Devolutions
Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve
account discovery scan results.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| devolutions | server | to 2026.2.7 (exc) |
| devolutions | server | to 2026.1.22 (exc) |
| devolutions | server | to 2026.2.5 (inc) |
| devolutions | server | to 2026.1.21 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-882 |