What is CVE-2026-17568?
An improper access control vulnerability in the role membership management endpoint of Devolutions Server allows an authenticated non-administrative user with 'user-group membership management' permission to escalate privileges to administrator via a crafted API request. This issue affects Devolutions Server.
Azərbaycanca: Devolutions Server-də rol üzvlüyünün idarə edilməsi endpointində düzgün giriş nəzarətinin olmaması (improper access control) səbəbindən, 'user-group membership management' icazəsinə malik autentifikasiya olunmuş qeyri-administrator istifadəçi xüsusi hazırlanmış API sorğusu vasitəsilə administrator imtiyazlarına yüksələ bilər. Bu zəiflik Devolutions Server məhsuluna təsir edir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Devolutions
FAQ2
Who can exploit CVE-2026-17568?
An authenticated non-administrative user with 'user-group membership management' permission can exploit this vulnerability.
What is the impact of a successful exploit of CVE-2026-17568?
The user can escalate privileges to administrator via a crafted API request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.