CVE-2026-15637 Details
Description
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
A vulnerability exists in Devolutions Server in versions 2026.2.11 and earlier, as well as 2026.1.22 and earlier. The issue arises from improper authorization in the Privileged Access Management (PAM) SSH key and certificate retrieval endpoints. This flaw allows an authenticated low-privileged user to access and disclose the private key of an SSH key or certificate PAM credential by directly referencing the credential identifier.
Users are advised to upgrade to Devolutions Server versions 2026.1.23.0, 2026.2.12.0 or higher.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0024/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| devolutions devolutions server | < 2026.1.23.0 >= 2026.2.0.0, < 2026.2.12.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | Reanalysis | [email protected] |
| Jul 20, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |