CVE-2026-12755
Last modified
CVE-2026-12755 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Undergoing Analysis
Frequently Asked Questions
What is CVE-2026-12755?
How severe is CVE-2026-12755?
How do I fix CVE-2026-12755?
Are you affected by CVE-2026-12755?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
