Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated
user with the UserGroupsView permission to coerce server-side
authentication to an attacker-controlled host, exposing PAM provider
credentials as a NTLMv2 challenge-response, via a crafted DomainName
parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0020/ |
|
Thu, 25 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions server |
|
| Vendors & Products |
Devolutions
Devolutions server |
Thu, 25 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge-Response in Devolutions Server | Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge‑Response in Devolutions Server |
Thu, 25 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge-Response in Devolutions Server |
Thu, 25 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 25 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter. | |
| Weaknesses | CWE-1284 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-06-25T14:52:29.837Z
Reserved: 2026-06-19T19:30:39.329Z
Link: CVE-2026-12755
Updated: 2026-06-25T14:50:50.494Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T22:30:15Z