[0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1)
Authenticated Devolutions Server admins can bypass PAM checks and run SYSTEM PowerShell via a test-script endpoint.
0day Rubbish Research Team disclosed a missing-authorization flaw in Devolutions Server (DVLS) 2026.2.14.0. An authenticated administrator who lacks a PAM licence and PAM role can bypass the PAM entitlement gate and run arbitrary PowerShell as NT AUTHORITY\SYSTEM through the test-script endpoint (CWE-862). CVSS is 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). A reproducible proof-of-concept is claimed; the post does not assign a CVE or report exploitation in the wild.
- Affects Devolutions Server (DVLS) 2026.2.14.0.
- Administrator without a PAM licence or PAM role can reach the test-script endpoint.
- Bypass yields arbitrary PowerShell as NT AUTHORITY\SYSTEM; CVSS 9.1.
- Requires high privileges; no CVE or in-the-wild exploitation stated.
Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in Devolutions Server (DVLS) 2026.2.14.0. Type: PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (CWE-862) CVSS: 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) Impact: arbitrary PowerShell execution as NT AUTHORITY\SYSTEM on the Devolutions Server host Authentication: authenticated administrator (no PAM licence, no PAM role) Full technical analysis and a...
This source does not provide full text. Read it at seclists.org.