Sceawere

Vulnerability Detail

CVE-2026-100287UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Devolutions Server Attachment Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
9h ago
Vendor
Devolutions
Product
Server
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-29T16:17:04.543Z",
  "pubdate": "2026-09-29T16:17:04.543Z",
  "executiveSummary": "A critical authorization vulnerability exists in the attachment history API of Devolutions Server versions 2026.3.5.0 and earlier. The flaw permits authenticated, low-privileged users to execute unauthorized operations on vault attachments.\nSpecifically, the API fails to properly validate user permissions before executing delete or restore commands. This vulnerability exposes the integrity and availability of sensitive vault data to malicious actors who possess legitimate low-level credentials.\nThe risk implication is significant as it allows for the permanent destruction of sensitive files stored within the application, leading to potential data loss scenarios. Attackers require a valid user session to reach the vulnerable API endpoints, but no elevated privileges are necessary to perform these destructive actions.\nThis vulnerability highlights a failure in server-side access control mechanisms during object state transitions within the attachment history component.",
  "technicalDetails": "The vulnerability resides within the attachment history API component of Devolutions Server, where insufficient server-side authorization checks allow for improper privilege validation. The system fails to enforce granular access controls for sensitive administrative or management functions related to vault attachment lifecycles.\nThe root cause is an insecure direct object reference (IDOR) or a lack of functional-level authorization in the API handling requests to the attachment history endpoints. When a request is submitted to modify the state of an attachment (e.g., permanent deletion or restoration from a previous version), the application verifies the requester's authentication status but fails to verify if the user possesses the authorization level required to manipulate the specific vault object.\nThe attack flow follows a predictable pattern: 1) The attacker authenticates as a low-privileged user within the Devolutions Server environment. 2) Using intercepting proxy tools or scripted HTTP clients, the attacker identifies the API endpoints responsible for attachment management and history recovery. 3) The attacker crafts a request, such as a DELETE or PATCH command, directed at the specific object ID of a target attachment. 4) Due to the missing authorization check, the server processes the request as if it originated from a privileged administrator, executing the requested change to the file system or database state. 5) The attachment is either permanently deleted from the vault or restored to an unauthorized state, depending on the attacker's intent.\nThis exploit is particularly dangerous because it bypasses the standard UI-based restrictions that would normally hide such operations from low-privileged users. The impact is a direct compromise of the confidentiality, integrity, and availability of stored credentials and sensitive documents. An attacker can systematically prune attachment history or purge specific files without leaving audit trails attributed to an authorized administrator, provided the initial authentication hurdle is cleared.\nThe affected versions include Devolutions Server 2026.3.5.0 and all preceding releases. Exploitation does not require network-level access beyond what is standard for an authenticated user, making this a high-impact vulnerability for internal threats or compromised low-privilege accounts."
}
CVE-2026-100287: Devolutions Server Attachment Authorization Bypass (MEDIUM Severity, CVSS: 5.4) | Sceawere