Devolutions Server是加拿大Devolutions公司的服务器设备。 Devolutions Server 2026.2.4.0至2026.2.12.0版本和2026.1.23.0及之前版本存在授权问题漏洞,该漏洞源于角色成员管理端点访问控制不当,可能导致认证的非管理员用户通过特制的API请求将权限提升为管理员。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Devolutions | Server | < 2026.1.24 |
affected |
2026.2.4.0< 2026.2.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Devolutions | Server | 0 ~ 2026.1.24 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17570 | Devolutions Server权限绕过致凭证泄露漏洞 | |
| CVE-2026-17569 | Devolutions Server 信任管理问题漏洞 |
No comments yet