Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.
History

Thu, 25 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Title Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge-Response in Devolutions Server Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge‑Response in Devolutions Server

Thu, 25 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authenticated PAM AD Discovery Credential Exposure via NTLMv2 Challenge-Response in Devolutions Server

Thu, 25 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 25 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.
Weaknesses CWE-1284
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-06-25T14:52:29.837Z

Reserved: 2026-06-19T19:30:39.329Z

Link: CVE-2026-12755

cve-icon Vulnrichment

Updated: 2026-06-25T14:50:50.494Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T17:00:11Z