Back to search
CVE-2025-11957
Published: Oct 22, 2025
Modified: Nov 25, 2025
PUBLISHED
Description
Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.
| Vendor | Product | Versions |
|---|---|---|
Devolutions | Server | affected 0 - <= 2025.2.12.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now