CVE-2026-17568
Received Received - Intake

Privilege Escalation in Devolutions Server

Vulnerability report for CVE-2026-17568, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Devolutions Inc.

Description

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
devolutions server From 2026.2.4.0 (inc) to 2026.2.12.0 (inc)
devolutions server 2026.1.23.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper access control flaw in Devolutions Server's role membership management endpoint. An authenticated non-administrative user with specific permissions can exploit a crafted API request to escalate their privileges to administrator level.

Detection Guidance

To detect this vulnerability, check if your Devolutions Server version falls within the affected range (2026.2.4.0 through 2026.2.12.0 or 2026.1.23.0 and earlier). Review API logs for unauthorized privilege escalation attempts or non-administrative users modifying role memberships.

Impact Analysis

An attacker with basic user access could gain full administrative control over the Devolutions Server, potentially accessing sensitive data, modifying configurations, or disrupting operations.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection standards like GDPR and HIPAA, which mandate strict access controls and data security measures.

Mitigation Strategies

Immediately update Devolutions Server to a version beyond the affected range. If an update is not immediately available, restrict non-administrative users from managing user-group memberships until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17568. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart