Vulnerability Description
Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-12755?
CVE-2026-12755 is a vulnerability with a CVSS score of 2.7 (LOW). Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side ...
How severe is CVE-2026-12755?
CVE-2026-12755 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12755?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.