PT-2026-40614 · Devolutions · Devolutions Server

CVE-2026-11890

·

Published

2026-05-13

·

Updated

2026-06-18

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2026.1.21 and 2026.2.5 Microsoft Message Queuing versions prior to Windows Server 2025
Description Devolutions Server contains improper access control in PAM account discovery, which allows an authenticated user to retrieve account discovery scan results.
Microsoft Message Queuing (MSMQ) is affected by a heap-based buffer overflow in the packet-parsing logic of the mqac.sys driver. This occurs when the driver fails to properly validate the length of a message header against the allocated buffer size during a Large Message request. An attacker can send a specially crafted binary packet to port 1801, where a subsequent Continuation packet contains a header size exceeding the initial allocation. This allows the attacker to overwrite adjacent function pointers and redirect them to a shellcode payload, resulting in unauthenticated remote code execution with SYSTEM privileges. Automated ransomware clusters have been observed weaponizing this issue to deploy memory-resident shells.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability regarding Devolutions Server. Apply the May 13, 2026, Security Update (KB5041132) and reboot the system to replace the mqac.sys driver. Block all inbound traffic on TCP port 1801 via hardware and host-based firewalls. Disable the MSMQ service if it is not required.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11890

Affected Products

Devolutions Server