External risk intelligence

Devolutions Server Temporary Access Workflow Improper Authorization Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2025-11957

Devolutions Server is a centralized privileged access management and remote connection platform commonly deployed as an internet-facing or externally reachable service to facilitate remote administration and access for distributed teams.

Devolutions Server

before 2025.2.14.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in Devolutions Server allows authenticated users to potentially approve access requests for others, leading to unauthorized access to sensitive information. The primary concern is confirming if your organization uses the affected product and is potentially exposed.

  • Unauthorized users can gain access.
  • Protects sensitive vault and entry data.
  • Confirm relevance and exposure immediately.

Attack Path

How an attacker could exploit the issue

An attacker with basic authenticated access could potentially exploit this vulnerability by crafting specific API requests. The attacker would start by logging into Devolutions Server with a basic user account. They would then use this access to manipulate the temporary access workflow, allowing them to approve their own or others' temporary access requests. This could grant them unauthorized access to sensitive vaults and entries.

  • Requires basic authenticated access.
  • Triggers via crafted API requests.
  • Leads to unauthorized vault access.

Live Threat

Current exploitation, exposure, and threat context

An authenticated basic user could exploit an improper authorization flaw in Devolutions Server's temporary access workflow to self-approve or approve access requests from other users. This could lead to unauthorized access to sensitive vaults and entries when crafted API requests are used.

  • Access to vaults and entries.
  • Crafted API requests can bypass controls.
  • Unauthorized access to sensitive data.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners responsible for Devolutions Server deployments are likely the first point of contact for addressing this vulnerability. The immediate priority should be identifying all instances of the affected software, assessing their business criticality and external reachability, and confirming the accountable owner for each. Once identified, a remediation plan can be developed based on the assessed risk.

  • Confirm Devolutions Server instance ownership.
  • Verify external exposure and asset criticality.
  • Plan remediation or implement compensating controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Devolutions Server?

Devolutions Server is a centralized platform designed for privileged access management and remote connection handling. Organizations use it to securely manage credentials, control access to sensitive vaults, and facilitate remote administration for distributed teams. Because it acts as a gateway for infrastructure management, it often serves as a critical component in maintaining secure, authorized access across an enterprise network.

What is the vulnerability in CVE-2025-11957?

This vulnerability involves an improper authorization flaw, specifically identified as CWE-639, which relates to authorization bypass through user-controlled keys. In the context of Devolutions Server, it means the system fails to correctly verify the permissions of a user during the temporary access request process. Consequently, a basic user can manipulate the workflow to grant themselves or others elevated access permissions they should not possess.

How does an attacker trigger this bug?

An attacker must already have a basic authenticated account to trigger this vulnerability. They use this valid account to send specifically crafted API requests to the server. Simply interacting with the web interface or being an unauthenticated visitor does not trigger the vulnerability; the process requires the ability to interact with the temporary access workflow via these manipulated API calls to bypass standard authorization checks.

Is my Devolutions Server instance at risk?

If you are running an affected version, your instance is at higher risk if it is configured to be internet-facing. According to Halo Surface Signal, Devolutions Server is frequently deployed as an externally reachable service to support remote teams. Instances that are exposed to the internet face a broader attack surface, increasing the likelihood that an attacker could reach the API and attempt to exploit the authorization flaw.

How should I respond to this threat?

Begin by identifying all deployed instances of Devolutions Server within your environment to determine which are running vulnerable versions. Prioritize those that are internet-facing or hold highly sensitive data. Once identified, locate the responsible application owners to evaluate the business criticality and coordinate a plan for remediation or the implementation of necessary compensating controls to secure the temporary access workflow.

References