[WID-SEC-2026-0958] Devolutions Server: Mehrere Schwachstellen CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 01.04.2026 Stand 02.04.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Windows Produktbeschreibung Devolutions Server ist eine selbstgehostete, zentralisierte Plattform zur Verwaltung und Freigabe von Passwörtern, Verbindungsdaten und Zugriffen in IT-Teams Produkte 01.04.2026 Devolutions Server <2026.1.12.0 Devolutions Server <2025.3.18 Angriff Angriff Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Devolutions Server ausnutzen, um Administratorrechte zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in Devolutions Server (CVSS 8.8) allow a remote authenticated attacker to gain administrator privileges, bypass security controls, manipulate data, or disclose sensitive information. Affected versions are Devolutions Server before 2026.1.12.0 and before 2025.3.18. A mitigation is available, though specific patch or workaround details are not provided in the advisory.