{"id":"CVE-2026-93330","title":"Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.","summary":"Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-696"],"vendor":"Devolutions","product":"Server","affected":["Server < 2026.3.7.0"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:15.307","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93330","references":[{"url":"https://devolutions.net/security/advisories/DEVO-2026-0034/","label":"security@devolutions.net"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-29T15:40:47.793465Z"},"ingestedAt":"2026-09-29T16:39:33.271Z","slug":"CVE-2026-93330","body":"## Overview\n\nImproper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}