CVE-2026-17570
Received Received - Intake

Improper Access Control in Devolutions Server Reveals Credential Secrets

Vulnerability report for CVE-2026-17570, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Devolutions Inc.

Description

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
devolutions server From 2026.2.4.0 (inc) to 2026.2.12.0 (inc)
devolutions server 2026.1.23.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper access control issue in the PAM password history endpoints of Devolutions Server. An authenticated low-privileged user can exploit crafted API requests to disclose plaintext credential secrets.

Impact Analysis

An attacker with low privileges could gain access to plaintext passwords or other sensitive credentials stored in the system, potentially leading to unauthorized access to accounts or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive data, violating compliance requirements such as GDPR (data protection) and HIPAA (health information privacy), potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Update Devolutions Server to a version that is not affected by this vulnerability. Affected versions are 2026.2.4.0 through 2026.2.12.0 and 2026.1.23.0 and earlier. Apply the latest patches provided by Devolutions to address the improper access control issue in PAM password history endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17570. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart