Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-15637

AI Predicted 7.5 Difficulty: Easy EPSS 0.19% · P9

Possible ATT&CK Techniques 2AI

T1155 T1530 · Data from Cloud Storage

Affected Version Matrix 2

VendorProductVersion RangeStatus
DevolutionsServer< 2026.1.23affected
< 2026.2.12affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-15637

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: NVD (National Vulnerability Database)
Vulnerability Title
Devolutions Server 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Devolutions Server是加拿大Devolutions公司的服务器设备。 Devolutions Server存在授权问题漏洞,该漏洞源于PAM SSH密钥和证书检索端点授权不当,可能导致已验证的低权限用户通过直接对象引用凭证标识符来泄露SSH密钥或证书PAM凭据的私钥。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
DevolutionsServer 0 ~ 2026.1.23 -

II. Public POCs for CVE-2026-15637

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15637

登录查看更多情报信息。

Vendor Advisories for CVE-2026-15637 (1)

Same Patch Batch · Devolutions · 2026-07-14 · 4 CVEs total

CVE-2026-15642Devolutions Server 日志信息泄露漏洞
CVE-2026-15058Devolutions Server 授权问题漏洞
CVE-2026-15641Devolutions Server 授权问题漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-15637

No comments yet


Leave a comment