{"id":"CVE-2025-11957","title":"Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access…","summary":"Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access…","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L","cwe":["CWE-639"],"vendor":"devolutions","product":"devolutions_server","affected":["devolutions_server < 2025.2.14.0"],"patched":["devolutions_server 2025.2.14.0"],"published":"2025-10-22","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11957","references":[{"url":"https://devolutions.net/security/advisories/DEVO-2025-0015/","label":"security@devolutions.net"}],"tags":["nvd"],"epss":0.00327,"epssPercentile":0.23714,"ingestedAt":"2026-10-08T11:31:27.548Z","slug":"CVE-2025-11957","body":"## Overview\n\nImproper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults and entries via crafted API requests.\n\n## Affected\n\n- `devolutions_server < 2025.2.14.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `devolutions_server 2025.2.14.0`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}