Improper input validation in the PAM AD discovery endpoints in
Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated
user with the UserGroupsView permission to coerce server-side
authentication to an attacker-controlled host, exposing PAM provider
credentials as a NTLMv2 challenge-response, via a crafted DomainName
parameter.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0020/ |
|
History
Thu, 25 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge-Response in Devolutions Server | Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge‑Response in Devolutions Server |
Thu, 25 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge-Response in Devolutions Server |
Thu, 25 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 25 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter. | |
| Weaknesses | CWE-1284 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-06-25T14:52:29.837Z
Reserved: 2026-06-19T19:30:39.329Z
Link: CVE-2026-12755
Updated: 2026-06-25T14:50:50.494Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T17:00:11Z