Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9248

Опубликовано: 22 мая 2026
Источник: nvd
CVSS3: 2.6
EPSS Низкий

Описание

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request.

This issue affects :

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0
  • Devolutions Server 2025.3.20.0 and earlier

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Версия до 2025.3.22.0 (исключая)
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Версия от 2026.1.6.0 (включая) до 2026.1.19.0 (исключая)

EPSS

Процентиль: 9%
0.00186
Низкий

2.6 Low

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 2.6
github
2 месяца назад

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault they cannot access via a crafted save request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

EPSS

Процентиль: 9%
0.00186
Низкий

2.6 Low

CVSS3

Дефекты

CWE-639