[0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1)
Authenticated Devolutions Server admins can bypass PAM checks and run SYSTEM PowerShell via a test-script endpoint.
0day Rubbish Research Team disclosed a missing-authorization flaw in Devolutions Server (DVLS) 2026.2.14.0. An authenticated administrator who lacks a PAM licence and PAM role can bypass the PAM entitlement gate and run arbitrary PowerShell as NT AUTHORITY\SYSTEM through the test-script endpoint (CWE-862). CVSS is 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). A reproducible proof-of-concept is claimed; the post does not assign a CVE or report exploitation in the wild.
62