CVE-2025-8353
UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.40%
- CWE
- CWE-446
- Published
- 2025-07-30
- Last modified
- 2026-03-12
Affected products
- Devolutions Server
Weakness type
Related vulnerabilities
- CVE-2025-52983 — Junos OS: After removing ssh public key authentication root can still log in
- CVE-2023-1768 — Symmetric agent data encryption fails silently