CVE-2025-0691

MEDIUM

Dovolations Server <2025.1.10.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.

References (1)

Core 1

Scores

CVSS v3 5.0
EPSS 0.0027
EPSS Percentile 18.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
devolutions/devolutions_server < 2025.1.10.0
Published Jun 05, 2025
Tracked Since Feb 18, 2026