CVE Database
/

CVE-2025-11957

Back to search

CVE-2025-11957

Published: Oct 22, 2025

Modified: Nov 25, 2025

PUBLISHED

Description

Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.

VendorProductVersions

Devolutions

Server

affected
0 - <= 2025.2.12.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now