CVE-2025-4493: Devolutions Server
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups by exploiting a user interface issue. This issue affects the following versions : * Devolutions Server 2025.1.3.0 through 2025.1.7.0 * Devolutions Server 2024.3.15.0 and earlier
Affected products
- Devolutions Devolutions Server: up to and including 2024.3.15.0; from 2025.1.3.0, up to and including 2025.1.7.0
Published 2025-05-28. Last modified 2026-06-17.