CVE-2025-8353CWE-446

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated…

Medium · published July 30, 2025

CVSS v3.1
5.9
EPSS
0%
Percentile
33.1
In the wild
Unconfirmed
What it is

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during standard checkout request processing.

The record
Technical detail
CVSS v3.1
5.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00398 · 33.1th percentile
Weakness
CWE-446 · UI Discrepancy for Security Feature
Published
2025-07-30T16:06Z
EPSS history
Timeline
  • 30 JUL 16:06Z
    UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated…
    cvelistv5