Sceawere
Vulnerability Detail
CVE-2026-100289UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Devolutions Server Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5
- Creation Date
- 9h ago
- Vendor
- Devolutions
- Product
- Server
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan token and perform internal network discovery and port scanning through the gateway via a crafted API request.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.0",
"pubDate": "2026-09-29T16:17:04.780Z",
"pubdate": "2026-09-29T16:17:04.780Z",
"executiveSummary": "This vulnerability is an Improper Authorization flaw identified within the gateway network scan token API of Devolutions Server versions 2026.3.5.0 and earlier.\nThe security weakness allows an authenticated user with low-level privileges to gain unauthorized access to network reconnaissance functionality that should be restricted.\nBy manipulating specific API requests, an attacker can generate a valid network scan token and orchestrate internal network discovery and port scanning activities through the gateway service.\nThe risk implication is significant as it facilitates lateral movement and reconnaissance, providing an attacker with visibility into internal network architecture, active hosts, and exposed services.\nExploitation requires the attacker to possess an active, low-privileged authenticated session on the target Devolutions Server instance.\nNo elevated privileges or administrative access are required to execute the exploit, making it an attractive vector for internal threat actors or compromised low-privileged accounts aiming to map the internal environment.",
"technicalDetails": "The vulnerability resides within the gateway network scan token API, a component intended to facilitate authorized network diagnostic tasks. The root cause is a failure to implement adequate authorization checks during the token generation process. Specifically, the API endpoint fails to validate whether the requester possesses the appropriate administrative or diagnostic permissions required to trigger network discovery operations.\nThe exploitation process begins once an attacker has established a baseline authenticated session as a low-privileged user within the Devolutions Server environment. The attacker crafts a specific HTTP request directed at the network scan token API. Because the backend service lacks the necessary authorization gates, it accepts the request from the unauthorized user and proceeds to generate a functional network scan token.\nUpon receiving this token, the attacker can leverage the gateway to perform operations that the security model originally intended to restrict. The attack flow proceeds as follows: First, the attacker invokes the compromised API endpoint to obtain a cryptographically signed or otherwise valid token. Second, the attacker utilizes this token to interact with the gateway service. Third, the gateway, believing the request is authorized based on the provided token, initiates active scanning processes.\nThe gateway performs internal network discovery and port scanning, interacting with local or remote endpoints accessible via the gateway's network segment. The payload behavior involves the gateway acting as a proxy for the attacker's reconnaissance queries. By iteratively querying the gateway with different parameters, the attacker can map internal IP ranges, identify live hosts, and perform port scanning to determine service availability and potential attack surfaces.\nThis vulnerability effectively bypasses intended security controls, allowing unauthorized internal reconnaissance. Post-exploitation impact includes the aggregation of technical intelligence regarding internal infrastructure, which can be utilized to craft further exploits against discovered services or sensitive assets reachable through the gateway. The lack of granular authorization in the API essentially grants low-privileged users the ability to abuse the gateway as an unintended reconnaissance tool, subverting the principle of least privilege within the Devolutions Server ecosystem."
}