CVE-2026-8407

Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.11.0 * Devolutions Server 2025.3.16.0 and earlier
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-12 17:16

Updated : 2026-06-17 11:03


NVD link : CVE-2026-8407

Mitre link : CVE-2026-8407

CVE.ORG link : CVE-2026-8407


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-862

Missing Authorization