---
id: CVE-2026-12755
title: |-
  Improper input validation in the PAM AD discovery endpoints in 
  Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated
   user with the UserGroupsView permission to coerce server-side 
  authentication to an attacker-contro…
summary: |-
  Improper input validation in the PAM AD discovery endpoints in 
  Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated
   user with the UserGroupsView permission to coerce server-side 
  authentication to an attacker-contro…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-1284
vendor: devolutions
product: devolutions_server
affected:
  - 'devolutions_server >= 2026.2.4.0, < 2026.2.9.0'
patched:
  - devolutions_server 2026.2.9.0
published: '2026-06-25'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12755'
references:
  - url: 'https://devolutions.net/security/advisories/DEVO-2026-0020/'
    label: security@devolutions.net
tags:
  - nvd
epss: 0.00365
epssPercentile: 0.27735
ingestedAt: '2026-06-29T15:48:27.787Z'
---

## Overview

Improper input validation in the PAM AD discovery endpoints in 
Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated
 user with the UserGroupsView permission to coerce server-side 
authentication to an attacker-controlled host, exposing PAM provider 
credentials as a NTLMv2 challenge-response, via a crafted DomainName 
parameter.

## Affected

- `devolutions_server >= 2026.2.4.0, < 2026.2.9.0`

## Remediation

Upgrade past the affected range:

- `devolutions_server 2026.2.9.0`
