CVE-2026-15641: CWE-863 in Devolutions Server
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
AI Analysis
Technical Summary
This vulnerability (CWE-863) in Devolutions Server affects versions from 2026.1.22 up to and including 2026.2.11. The issue lies in the access request status endpoint, where authorization controls are insufficient. An authenticated user with low privileges can exploit this flaw to approve their own pending access requests without going through the proper approval workflow, effectively bypassing intended access controls.
Potential Impact
An attacker with low-level authenticated access can escalate privileges by self-approving access requests that normally require higher-level approver authorization. This could lead to unauthorized access to sensitive resources or functions within the Devolutions Server environment. The confidentiality impact is high, integrity impact is low, and availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the affected endpoint and monitor for suspicious access request approvals. Avoid granting unnecessary privileges to low-privileged users to reduce risk.
CVE-2026-15641: CWE-863 in Devolutions Server
Description
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
CVSS v3.1
Score 7.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-863) in Devolutions Server affects versions from 2026.1.22 up to and including 2026.2.11. The issue lies in the access request status endpoint, where authorization controls are insufficient. An authenticated user with low privileges can exploit this flaw to approve their own pending access requests without going through the proper approval workflow, effectively bypassing intended access controls.
Potential Impact
An attacker with low-level authenticated access can escalate privileges by self-approving access requests that normally require higher-level approver authorization. This could lead to unauthorized access to sensitive resources or functions within the Devolutions Server environment. The confidentiality impact is high, integrity impact is low, and availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the affected endpoint and monitor for suspicious access request approvals. Avoid granting unnecessary privileges to low-privileged users to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- DEVOLUTIONS
- Date Reserved
- 2026-07-13T18:21:03.185Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a56811c68715ace43005268
Added to database: 07/14/2026, 18:34:04 UTC
Last enriched: 07/21/2026, 18:51:32 UTC
Last updated: 08/23/2026, 10:52:07 UTC
Views: 92
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.