Back to Database
Status published
Unknown
CVE-2025-13765
Exposure of email service credentials to users without administrative rights...
Vulnerability Description
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13765
Credits & Attribution
No credits recorded in the NVD database.
More from Devolutions
View All →CVE-2025-8353
UI synchronization issue in the Just-in-Time (JIT) access request approval...
Unknown
0
CVE-2025-8312
Deadlock in PAM automatic check-in feature in Devolutions Server allows...
Unknown
0
CVE-2025-6741
Improper access control in secure message component in Devolutions Server...
High
7.1
CVE-2025-6523
Use of weak credentials in emergency authentication component in Devolutions...
Critical
9.5
CVE-2025-5382
Improper access control in users MFA feature in Devolutions Server...
Unknown
0
Affected Vendor
Devolutions
View all reports →Affected Software
Server
Vulnerable Versions:
0
Timeline
Official Publish:
November 27th, 2025
Last Modified:
December 1st, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available