Devolutions Server Versions

Découvrez les nouveautés dans chaque version, avec des détails sur les fonctionnalités, les améliorations et les problèmes résolus.

janv.
févr.
mars
avr.
mai
juin
juil.
août
sept.
oct.
nov.
déc.
Devolutions Gateway 2026.2.4.028 juil. 2026
Fonctionnalités
  • Service - Added support for Session Recording Log (.slog) recording artifacts.
  • Service - Automatically retry transient Kerberos (KDC) connection drops to avoid occasional authentication failures.
  • Service - Write a boot stack trace file when running as a service, making startup failures easier to diagnose.
Devolutions Server and Console 2026.2.14.027 juil. 2026
Fonctionnalités

Server

  • PAM - Password history now requires the appropriate password permissions, preventing unauthorized access to previous passwords.
  • Web - Added RustDesk entry details to the web interface.
  • Web - Users with the Password Policies permission can now edit the password template directly from the password generator.

Console

  • Made a minor update.
Corrections

Server

  • Core - Fixed a privilege escalation issue where non-administrators could add themselves to administrator groups.
  • Core - Fixed an issue where the NetBox synchronizer API token was visible to users with view-only access.
  • Core - Fixed an issue where custom permission sets could be removed when saving unrelated system settings.
  • Core - Fixed an issue where domain users could not be linked to user groups.
  • Core - Fixed an issue where Passwordstate v10 entries incorrectly required an API key when saving.
  • Core - Fixed an issue where the Duo automatic multi-factor preference was not retained after login.
  • Core - Fixed an issue where the Duo SMS button did not send passcodes from the login window.
  • PAM - Fixed an error that prevented editing PAM accounts from Remote Desktop Manager.
  • PAM - One-time password secret keys are no longer sent to clients; codes are now always generated by the server.
  • Web - Fixed an issue where permission changes could not be saved from the batch grant access dialog.
  • Web - Fixed an issue where the password generator ignored the parent folder's password policy when creating entries.
Devolutions Launcher 2026.2.16.021 juil. 2026
Fonctionnalités
  • Added Keeper importers (CSV and JSON) for importing entries from Keeper.
Corrections
  • Fixed a tile disappearing from a custom tile layout after it was closed.
  • Fixed browsing for accounts failing in 1Password when using 'My account settings'.
  • Fixed connecting to a 1Password account protected by Duo, where a loading indicator could stay stuck after the Duo prompt completed.
  • Fixed Devolutions Cloud workspaces set to always prompt for login (Force login) re-prompting repeatedly while resolving privileged account (PAM) credentials.
  • Fixed DVLS workspaces immediately prompting to reconnect right after clicking Log Off.
  • Fixed session recording not starting for Devolutions Cloud entries that connect through the Devolutions Gateway.
  • Fixed the Devolutions Cloud dashboard switching on its own to a different vault while left idle.
  • Fixed the File Explorer local pane opening as a separate window on another monitor.
  • Fixed the one-time password (OTP) timer for sessions linked to privileged account (PAM) credentials.
  • Fixed the Privileged Account credential mode missing from user-specific settings for users without a PAM license.
Devolutions Launcher 2026.2.14.015 juil. 2026
Fonctionnalités
  • Added back Impero Connect (Netop) support.
  • Added several AI Assistant improvements, including configurable chat panel positioning, toolbar overflow fixes, reduced SSH command lag, and on-demand Copilot CLI download.
  • Added support for using an asset's serial number as a variable in entry names.
  • Updated the DVLS new-version notification to open the release notes.
Corrections
  • Fixed "Open link in new window" changing focus to the new window for website entries.
  • Fixed a pagination issue when browsing Entra ID tenants.
  • Fixed an error that could occur when canceling the account sign-in prompt during startup; the application now continues loading normally.
  • Fixed an issue where remote PowerShell scripts could run locally instead of on the target machine.
  • Fixed an unhandled error when the cloud account login returned a 403 Forbidden response.
  • Fixed clickable links being hard to read in certain text views.
  • Fixed Launcher access being blocked for users whose RDM platform access was denied; Launcher is now gated on its own access right.
  • Fixed multiple errors that occurred when changing a workspace's host and logging in.
  • Fixed multiple issues in the Amazon S3 file explorer.
  • Fixed right-click actions being disabled in the remote file explorer's file grid.
  • Fixed smart card certificate and PIN RDP logon that was broken by Windows update KB5066835.
  • Fixed some remote tools ignoring the entry's configured username format and always falling back to domain\user.
  • Fixed the AI assistant's entry search to respect each user's view permissions, so entries a user cannot view are no longer returned.
  • Fixed the Dashlane integration by prompting for a device registration token during login.
  • Fixed the Devolutions Cloud username prompt requiring a password when only a username was needed.
  • Fixed the login page becoming non-interactive on RDS/Citrix sessions.
  • Fixed the SFTP local pane not restoring the opened folder after a refresh.
Devolutions Server and Console 2026.2.12.014 juil. 2026
Fonctionnalités

Server

  • Core - Added a Devolutions Send region selector in Server settings for .com and .eu regions.
  • [CVE-2026-15058] Core - Improved security by preventing users from deleting another user's messages.
  • [CVE-2026-15637] PAM - Improved security by preventing unauthorized access to SSH private keys.
  • [CVE-2026-15641] Core - Improved security by preventing users from approving their own pending access requests.

Console

  • [CVE-2026-15642] Core - Improved security by preventing Azure Key Vault secrets from being exposed in recovery kits when sensitive data is excluded.
Corrections

Server

  • Core - Password policy validation errors now provide clear, actionable feedback instead of a generic server error.
  • PAM - Fixed an issue preventing users with PAM management permission from selecting JIT groups.
  • PAM - Fixed an issue where previously selected JIT elevation groups could appear blank or disappear.
  • PAM - Fixed an issue where SSH provider timeout settings were ignored, causing endless loading when a host was unreachable.
  • Web - Fixed the Logs dashboard menu positioning for the "Last 7 days" filter.
Devolutions Gateway 2026.2.3.08 juil. 2026
Fonctionnalités
  • Service - Improved diagnostic logging for sessions to make troubleshooting easier.
Corrections
  • Service - Fixed terminal session live-view (shadowing) display sizing and a crash that could occur with very long output lines.
Devolutions Launcher 2026.2.13.06 juil. 2026
Fonctionnalités
  • Added multiple tools, including custom installer.
  • Removed the Go-offline option for PAM vaults in Devolutions Cloud.
Corrections
  • Fixed a crash caused by an inherited password policy with an unsupported mode.
  • Fixed a crash when reloading a DVLS workspace after saving.
  • Fixed a DVLS login loop that opened multiple browser windows during authentication.
  • Fixed a memory leak when closing undocked containers.
  • Fixed an error after switching accounts in Devolutions Cloud.
  • Fixed Azure SQL Active Directory Interactive login.
  • Fixed issue where you could filter by passwords in the Password List overview.
  • Fixed SSMS entries with Integrated Security opening the usage/help screen instead of connecting (SSMS v20).
  • Fixed Terminal command entry script execution on Before Close events.
  • Fixed the missing Last Comment button and search in session comment dialogs.
  • Fixed the RDP logoff action on Windows Core servers.
Devolutions Server and Console 2026.2.11.06 juil. 2026
Fonctionnalités

Server

  • PAM - Improved the Grant temporary access screen by fixing scrolling when browsing the list.
  • PAM - Reduced Active Directory lookups when resolving approvers, improving responsiveness during approval actions.
  • Web - Added support for X.509 certificate credentials, allowing certificate entries created in Remote Desktop Manager to be viewed and used in the web interface.

Console

  • Made a minor update.
Corrections

Server

  • Core - (CVE-2026-14536) Fixed an issue where MFA policies were not enforced when no default MFA method was configured.
  • Core - Fixed an intermittent login loop affecting YubiKey and MFA users.
  • Core - Fixed an issue where users using Alternate Email MFA were no longer recognized as having MFA enabled after updating.
  • Core - Fixed duplicated telemetry events and improved cleanup of outdated events.
  • Core - Made multiple UI fixes.
  • PAM - Fixed a missing Checkout permission message when approving a checkout without the required permission.
  • PAM - Fixed an issue where users without the required vault access could appear as approvers.
  • Web - Fixed a loading overlay that blocked interaction with the compromised password dialog.
  • Web - Fixed an issue preventing Equivalent URLs from being configured on Web Browser entries.
  • Web - Fixed the Copy to clipboard action in the password list.

 

Devolutions Launcher 2026.2.12.026 juin 2026
Fonctionnalités
  • Removed an unnecessary password field from the Pleasant Password Server two-factor authentication dialog.
Corrections
  • Fixed a crash at login when using Devolutions Cloud workspaces with no favorites configured.
  • Fixed a deadlock that could cause WinRM connections to stop responding.
  • Fixed a deadlock that could occur when closing a Hyper-V session tab.
  • Fixed a potential crash when unlocking the application.
  • Fixed an autofill issue with special characters in the OpenVPN GUI.
  • Fixed an issue where enabling "Prompt for credentials on client" on an RDP entry caused saved credentials to be ignored.
  • Fixed an issue where opening an SSH connection collapsed all items in the user vault.
  • Fixed an issue where right-clicking after opening a session with double-click would unexpectedly steal the screen focus.
  • Fixed certain file dialogs not allowing files to be saved with names that do not yet exist.
  • Fixed ControlR dashboard entries failing to open when the Use My Account Settings option is enabled.
  • Fixed Devolutions Agent jumped connections not respecting the configured embedded or external display mode.
  • Fixed entries in Devolutions Cloud workspaces with User Specific Settings not appearing in the password manager browser extension.
  • Fixed expired ControlR authentication tokens failing to refresh automatically.
  • Fixed folder and file pickers crashing when a network path was selected.
  • Fixed the automatic reconnect on activity feature in the user vault.
  • Fixed the Bitwarden synchronizer creating shortcuts on workspaces that do not support them.
  • Fixed User Vault forcing a full data reload on every refresh in DVLS workspaces.
Devolutions Server and Console 2026.2.9.023 juin 2026
Fonctionnalités

Server

  • Core - Improved Brandfetch icon display to better match the active application theme.
  • Core - Improved service security by correcting the DVLS Scheduler service registration path.
  • Core - Updated the OTP authentication mode name from "Username and password" to "Configured" for consistency with Remote Desktop Manager.
  • Core - Added a clearer message when the DVLS Free user limit is reached during first-time SSO sign-in.
  • PAM - Added a Message column to recent activities exports to include elevation request details.
  • PAM - Improved security of Active Directory browse endpoints against credential-coercion and unauthorized-access attacks.

Console

  • Made minor updates.
Corrections

Server

  • Core - Fixed Active Directory synchronization and domain configuration errors in environments with overlapping domain names.
  • Core - Fixed an issue preventing users from changing the preferred domain controller when the current controller was unavailable.
  • Core - Fixed syslog messages that could fail RFC 5424 validation and interfere with event processing.
  • Core - Made multiple UI fixes.
  • PAM - Fixed Azure account password resets.
  • Web - Fixed an issue where the Launch button could disappear when an entry was checked out by another user.
  • Web - Fixed log comment edits being lost after refreshing the page.
  • Web - Fixed the System Settings search box not returning results.
Devolutions Launcher 2026.2.11.017 juin 2026
Fonctionnalités
  • Added back the Caps Lock indicator on the application login prompt.
  • Added back the Parallels 2X Client add-on.
  • Added Proxmox credential type support in the free version.
  • Improved ControlR add-on authentication by replacing privileged access token login with Username, Password, and Bearer Token options.
  • Improved performance on Devolutions cloud workspace.
  • Removed the no longer functional "Show Application Tools Tab" option from the UI layout settings.
  • Removed the SFTP panel splitter when the section is hidden.
Corrections
  • Fixed a crash that could occur when a window was closed during initialization.
  • Fixed a crash when the DisableToolsMenu group policy was enabled.
  • Fixed a data refresh issue with Devolutions cloud workspaces.
  • Fixed a possible crash caused by invalid color conversion.
  • Fixed an issue where only one Windows Terminal process could be opened at a time.
  • Fixed embedded RDP sessions not filling the screen in full screen mode when using Smart Sizing.
  • Fixed GPT 5.5 model availability in the AI Assistant.
  • Fixed Hub workspace entries becoming inaccessible.
  • Fixed integrated security not filling the username automatically.
  • Fixed PowerShell sessions launched with Run As credentials to display a proper error message when the launch fails instead of silently failing.
  • Fixed several UI issues in the prompt for pasting multi-lines in terminals.
  • Fixed single-line break pasting triggering a multi-line warning in terminals.
  • Fixed SQL Server workspace being incorrectly forced into in-memory caching mode after an edit.
  • Fixed SSH Shell issue where selecting the tab did not properly focus the terminal.
  • Fixed the calendar date picker watermark to use the current culture instead of the operating system culture.
  • Fixed the default paths for the SCCM add-on.
  • Fixed the linked picture not being saved when adding a new contact entry.
  • Fixed undocked sessions pulling the main window to the front.
Devolutions Server and Console 2026.2.7.016 juin 2026
Fonctionnalités

Server

  • Core - Website Legacy entries can no longer be edited and must be converted before use. The option to permanently dismiss the conversion notice has also been removed.
  • Core - Improved loading performance for repository assignments, including the Batch Grant Access window.
  • PAM - Added requested elevation details to reports.
  • PAM - Added visibility into which approvers received temporary access and PAM checkout requests.
  • PAM - Prevented users from approving their own checkout requests through linked accounts when self-approval is disabled.

Console

  • Made minor updates.
Corrections

Server

  • Core - Fixed a security issue where ticketing service credentials (ServiceNow and Jira) could be viewed by authenticated users through data source settings.
  • Core - Fixed a security issue where duplicating a folder could expose attachments and handbook pages to users without access to the original content.
  • Core - Fixed an issue where social-login entry metadata could be visible to vault members who were explicitly denied access to those entries.
  • Core - Fixed a privilege escalation issue that could allow users creating vaults or PAM providers to assign themselves System Administrator rights.
  • Core - Fixed a performance regression that caused system permission changes to take longer than expected to save.
  • Core - Fixed a synchronizer error that occurred when nested groups were deleted in Entra ID (Azure AD).
  • Core - Fixed an issue preventing orders from being created when they contained both a starter pack and additional licenses.
  • Core - Fixed an issue where changing a password on first login after a basic installation could fail.
  • Core - Fixed an issue where exported attachments and documents could become unusable after re-importing with attachments included.
  • Core - Fixed an issue where the "Template list only" mode was not enforced, allowing entries to be created without a template.
  • Core - Fixed an issue where variables were not resolved when unsealing entries or sending related notifications.
  • Core - Fixed false password-change audit logs and notification emails when updating non-credential Website entry settings.
  • PAM - Fixed missing permission checks on discovery scan results, ensuring only authorized users can access discovery data.
  • PAM - Fixed PostgreSQL accounts incorrectly appearing out of sync after successful password resets.
  • PAM - Fixed the "MFA on checkout" default setting not being saved.
  • Web - Fixed a JavaScript error when viewing entry details containing deserialization errors under Reports > Diagnostic > Entries.
  • Web - Fixed an issue where deleting an entry could trigger an error and leave the connections tree in an incorrect state until the page was refreshed.
  • Web - Fixed an issue where unsupported AI Assistant providers appeared blank in the edit dialog and could cause the wrong provider to be saved.
  • Web - Fixed Synchronizer entries becoming unusable in the web interface when the synchronization mode was set to manual or inherited manual.
  • Web - Made UI fixes.
Devolutions Launcher 2026.2.9.012 juin 2026
Fonctionnalités
  • Hardened autofill and connection handbook input handling to prevent injections.
  • Added a "v9 deprecated" banner for v9 PasswordState entries.
  • Added the ability to use Yubikey PIV/PKCS as SSH key.
  • Added column sorting to the Favorites panel.
  • Added optional Username and Description columns to the Favorites panel.
  • Improved performance when filtering a vault.
  • Improved VPN image overrides to be less invasive and added an option to hide the overlay entirely.
  • Restored the Ivanti Secure Access Client add-on (previously known as Juniper Junos Pulse).
  • Restored the SCCM add-on.
Corrections
  • Fixed a Social Login spoofing vulnerability.
  • Fixed a crash in the AI Assistant when using an Ollama model that does not support tools.
  • Fixed a crash in the logs tab on a cloud workspace with no shared vault.
  • Fixed a crash when opening a contextual menu.
  • Fixed a crash when opening the Launcher without any workspaces.
  • Fixed a DVLS login loop that opened multiple browser windows.
  • Fixed an infinite loop when launching a host via a template.
  • Fixed an issue where the tray icon context menu could not be opened.
  • Fixed batch edit forcing host input when the host was linked or inherited.
  • Fixed CPU saturation issues in terminal servers.
  • Fixed favorites being empty in a Cloud workspace.
  • Fixed favorites not loading connections properly when they came from external vaults.
  • Fixed Hub workspaces making web calls while in offline mode.
  • Fixed PAM permission sets on temporary access approval.
  • Fixed Social Login having trouble detecting certain Twitter login buttons.
  • Fixed template selection when using a host with Devolutions Agent.
  • Fixed underscores and other special characters being skipped in entry names when browsing from Favorites.
  • Fixed undocked sessions not saving their size and position per connection.
Devolutions Gateway 2026.2.2.09 juin 2026
Corrections
  • Service - Restored compatibility with version 1 update manifests so update checks work correctly with newer agents.
Devolutions Launcher 2026.2.8.08 juin 2026
Fonctionnalités
  • Added a system setting to hide the vault size warning banner.
  • Added support for opening entries from notifications across multiple vaults.
  • Added the ability to use a linked account (user vault) for the Run as tab.
  • Added XLSX export for report grids.
  • Improved agent connections to survive RDP reconnections.
  • Improved the Docker container shell to open in an embedded tab.
  • Improved the Docker container shell to prefer bash over /bin/sh.
  • Removed automatic license assignment for new DVLS users.
Corrections
  • Fixed a command injection vulnerability caused by an unquoted SSH elevation username.
  • Fixed a crash in the Secret Server account selection dialog.
  • Fixed a PowerShell injection issue in VMware Remote Console connections.
  • Fixed a regression that disabled IME input in password fields.
  • Fixed an issue where embedded opened entries were disabled when opened from the user vault.
  • Fixed an issue where the User Principal Name could cause the application to hang when it was recognized as a group.
  • Fixed double-click handling for non-RDP entries in the CyberArk dashboard.
  • Fixed several issues with favorites treeview.
  • Fixed temporary access not working for inherited VPNs.
  • Fixed text color for entries in the Favorites view.
  • Fixed the $HOST$ variable being incorrectly trimmed in Microsoft SQL Server connections.
  • Fixed the rename login button incorrectly appearing for workspaces that don't support it.
Devolutions Server and Console 2026.2.5.08 juin 2026
Fonctionnalités

Server

  • Core - Secured ticketing integration credentials so they are no longer visible to non-administrative users.
  • Core - Restricted access to deleted user group details to authorized administrators only.
  • Core - Added a global setting to disable the AI Assistant for all users.
  • Core - Added AI Assistant controls to Entry Type Availability settings for easier administration.
  • Core - API messages now match the language used in the web interface.
  • PAM - Password Rotation Schedules now follow your configured date and time format.
  • PAM - Improved the message shown when a password update is still pending, replacing provider errors with clearer information.
  • Web - DVLS now automatically uses your browser's language when you sign in, unless you have selected a different language.

Console

  • Made minor updates.
Corrections

Server

  • Core - Fixed an issue where updating the server could cause valid licenses to disappear when an expired license was present.
  • Core - Fixed password rotation issues affecting shared SQL accounts across multiple DVLS instances.
  • Core - Fixed SQL connection string passwords being written to logs in plain text during configuration reloads.
  • PAM - Fixed a script injection vulnerability in built-in PAM provider scripts.
  • PAM - Fixed adding PAM accounts to existing vaults without a valid PAM license.
  • PAM - Fixed an issue where Azure SQL accounts in the infrastructure vault were incorrectly shown as out of sync.
  • PAM - Fixed an issue where scans of unresponsive Windows targets could block future account scans.
  • PAM - Fixed SSH provider connections through the Gateway.
  • PAM - Fixed the Default Security section appearing for administrators without System Settings access.
  • Web - Fixed an error when closing web remote sessions and corrected the displayed hostname on disconnect.
Devolutions Gateway 2026.2.1.04 juin 2026
Fonctionnalités
  • Installer - Added certificate checks during installation so invalid certificate setups are caught earlier.
  • Service - Added experimental Kerberos-based credential injection support (behind unstable option).
  • Service - Added experimental transparent routing through the Agent Tunnel.
  • Service - Improved network scanning with better targeting and more consistent scan results.
  • Service - Reject recording uploads when recording storage is full to prevent incomplete recordings.
Devolutions Server and Console 2026.2.4.04 juin 2026
Fonctionnalités

Server

  • Core - Added a certificate-based Conditional Access Policy for certificate authentication.
  • Core - Added a dedicated AI Assistant entry in DVLS.
  • Core - Added a new credential mode to save and autofill social logins with the Password Manager extension.
  • Core - Added in-app notifications when a new DVLS server version is available.
  • Core - Added support for Microsoft Entra ID authentication using delegated permissions.
  • Core - Added the ability to configure the number of simultaneous checkouts allowed for an entry.
  • PAM - Added the ability to configure a default elevation group during checkout.
  • PAM - Added the option to require MFA when checking out a PAM account.
  • Web - Added Brandfetch auto-complete support when creating website entries.
  • Core - Added a search bar in the user selection dialog when creating a new domain user, searchable by sAMAccountName, displayName and OU.
  • Core - Added CVE vulnerability checks on the security dashboard with upgrade recommendations.
  • Core - Added the ability to filter entries by connection type through the REST API.
  • Core - Email notifications now use the user's configured language preference.
  • Core - Improved contractor user management with a redesigned onboarding experience, automatic password generation, and clearer disabled user indicators.
  • Core - Reduced the in-app trial period from 30 days to 14 days.
  • PAM - Added a "Skip TLS validation" option for the Windows provider.
  • PAM - Added support for using the provider account for SSH password heartbeat when target accounts have SSH access disabled.
  • PAM - Enhanced password rotation scheduling with more flexible configuration options.
  • PAM - Improved access requests to include the full hierarchy of linked connections.
  • Web - Added a button to clear all user notifications.
  • Web - Added a Convert button to the legacy website banner for faster entry conversion.
  • Web - Added a notification in the Administration Dashboard when a new DVLS version is available.
  • Web - Added vertical navigation in the Administration and Reports areas to make settings easier to find.
  • Web - Extended user synchronizer support in the web interface.

Console

  • The passwords file generated during a Basic Install now includes the SQL Express server/instance name for easier follow-up installs.
Corrections

Server

  • Core - Fixed a missing translation when requesting access to available vaults.
  • Core - Fixed a NullReferenceException that could occur when a deleted connection notification was processed.
  • Core - Fixed a portable license error ("Invalid license: RDM") on first login.
  • Core - Fixed a regression where Custom permissions behaved as Denied in web and RDM clients.
  • Core - Fixed a regression where vault assignments were not applied during user group import.
  • Core - Fixed a SQL timeout when renaming folders containing a large number of entries.
  • Core - Fixed an Access Denied error when non-admin users tried to add an entry from a template.
  • Core - Fixed an error when opening Duo MFA settings and improved invalid credential validation.
  • Core - Fixed an error when starting a trial with an no email address.
  • Core - Fixed an issue where duplicating a folder did not copy sub-entries.
  • Core - Fixed an issue where entry types disappeared from Type Availability when the last selected vault was content-restricted.
  • Core - Fixed an issue where removing an expired license incorrectly prompted for DVLS Free.
  • Core - Fixed attachments being lost when moving entries to another vault.
  • Core - Fixed DVLS being unable to connect to SQL Server on Linux when TLS encryption was enabled.
  • Core - Fixed Entra App Proxy pre-authentication failing when the DVLS account had MFA enforced.
  • Core - Fixed linked external vault information not being saved when linking an SSH key.
  • Core - Fixed missing translation and username details in temporary access approval emails.
  • Core - Fixed Syslog over TCP messages not being RFC 6587 compliant, preventing ingestion by some collectors.
  • Core - Fixed the "Do not show again" option not working in the Clipboard Privacy warning dialog.
  • Core - Fixed trailing spaces being saved in Tags and in Notification Subscription "Exact expression" parameters.
  • Core - Fixed User Settings Vault and Global settings not working for non-admin users in RDM.
  • Gateway - Fixed an issue where "Ping all Gateways" incorrectly reported failures.
  • Gateway - Fixed an issue where Gateway vault security incorrectly applied to PAM providers.
  • Gateway - Fixed GatewayManager creating a short-lived, undisposed HTTP client for every request, which could lead to socket exhaustion.
  • Gateway - Fixed the Update button remaining disabled after deleting a configured Gateway.
  • PAM - Fixed a regression where inherited OTP no longer worked on PAM accounts.
  • PAM - Fixed an issue where admins appeared as approvers even when disabled in settings.
  • PAM - Fixed an issue where approval through role/group permissions did not work.
  • PAM - Fixed checkout approvers not appearing in the approvers list when no PAM license is assigned.
  • PAM - Fixed having to scroll to access buttons in Reports > PAM Check-out requests.
  • PAM - Fixed incorrect "license required" messages shown to licensed PAM users.
  • PAM - Fixed PAM account details remaining visible while the account was checked out.
  • PAM - Fixed the PAM scheduler hanging on local Windows account scans when the target stopped responding.
  • PAM - Fixed the Windows Local Account provider template scan returning no results.
  • Web - Fixed a toast notification incorrectly showing "Not found" when deleting entries.
  • Web - Fixed a TypeError when opening Advanced Search as a user without a user vault.
  • Web - Fixed RDP/VNC/ARD left mouse clicks triggering a right-click in the web client when running in Firefox.
  • Web - Fixed the SSH web app not prompting for the private key passphrase when one was required.
  • Web - Fixed unnecessary icon cache fetches caused by virtual scrolling.
  • Web - Fixed web RDP sessions not invoking the KDC Proxy, causing Kerberos authentication to fall back to NTLM.
  • Web - Made multiple UI fixes.

Console

  • Core - Fixed additional access URIs not being editable in the Kestrel.
  • PAM - Fixed an issue where account discovery results were not always re-encrypted after an encryption key change.
Devolutions Launcher 2026.2.7.03 juin 2026
Fonctionnalités
  • Added a gateway connectivity test to the PAM service.
  • Added a group policy to hide the Quick Connect prompt confirmation message.
  • Restored the 'Open as SFTP/SCP' option for all session types.
Corrections
  • Fixed passwords being loaded into Quick Search for users who lack the required permissions.
  • Fixed a 1Password single sign-on error that could occur after multiple logins.
  • Fixed a 403 error on startup when loading Hub permission assignments.
  • Fixed a PowerShell injection vulnerability in VMRC connections.
  • Fixed agent connections so they survive an RDP reconnect.
  • Fixed an incorrect argument passed to SSMS after its latest updates.
  • Fixed an issue when moving or duplicating a folder that contains a virtual folder.
  • Fixed an issue where a user with the "Deleted entries" permission could not restore or delete history.
  • Fixed license assignment when editing a user in DVLS.
  • Fixed loss of Linked (vault) credentials, SSH keys, proxies, and gateways when a Hub Personal data source is converted to Hub Business.
  • Fixed management views opening the same window multiple times on the Free edition.
  • Fixed the private key dropdown not loading keys when on the User Vault tab.
  • Fixed the proxy bypass list not handling regular expressions correctly.
Devolutions Server and Console 2026.1.22.03 juin 2026
Fonctionnalités

Console

  • Made minor updates.
Corrections

Server

  • Core - Fixed a security issue where duplicating a folder could expose attachments and handbook pages to users without access to the original content.
  • Core - Fixed a security issue where ticketing service credentials (ServiceNow and Jira) could be viewed by authenticated users through data source settings.
  • Core - Fixed an issue where the "Template list only" mode was not enforced, allowing entries to be created without a template.
  • Core - Fixed login failures when using MaxMind GeoLite2 with location-based access policies.
  • PAM - Fixed missing permission checks on discovery scan results, ensuring only authorized users can access discovery data.
  • Web - Fixed an issue where deleting an entry could trigger an error and leave the connections tree in an incorrect state until the page was refreshed.
  • Web - Made UI fixes.
Devolutions Server and Console 2026.1.21.02 juin 2026
Fonctionnalités

Server

  • Core - Secured ticketing integration credentials so they are no longer visible to non-administrative users.
  • Core - Restricted access to deleted user group details to authorized administrators only.

Console

  • Made minor updates.
Corrections

Server

  • Core - Fixed an issue where updating the server could cause valid licenses to disappear when an expired license was present.
  • Gateway - Fixed false "Gateway down" notifications that could occur during periods of heavy load.
  • PAM - Fixed a script injection vulnerability in built-in PAM provider scripts.
  • PAM - Fixed an issue where Azure SQL accounts in the infrastructure vault were incorrectly shown as out of sync.
  • PAM - Fixed an issue where scans of unresponsive Windows targets could block future account scans.
Devolutions Server and Console 2026.1.20.01 juin 2026
Corrections

Server

  • [CVE-2026-9522] PAM - Fixed an access control issue affecting account discovery scan configurations.
  • [CVE-2026-9590] Core - Fixed a permission issue that could allow asset sections to be modified through the API without proper authorization.
  • Core - Fixed synchronizers running against sealed credentials without prompting for unsealing first.
  • Core - Fixed an error that prevented starting a trial when an invalid email address was entered.
  • Core - Fixed sign-in issues when using Entra App Proxy with MFA and pre-authentication enabled.
  • PAM - Fixed a regression where the OTP field was not displayed for checked-out accounts using inherited OTP settings.
  • Web - Fixed the Clipboard Privacy warning dialog's "Do not show again" option not being respected.
  • Web - Fixed trailing spaces being saved in Tags and Notification Subscription exact-match filters.

Console

  • Core - Fixed the inability to edit additional access URIs in the Kestrel configuration.
Devolutions Launcher 2026.2.5.01 juin 2026
Corrections
  • Fixed a "no license found" error when losing connection to the data source.
  • Fixed DUO errors and redirect failures during 1Password authentication.
  • Fixed error when the Hub data source connection dropped where the tray notification would not prompt in some cases.
  • Fixed issue in SSH entry where entering your 2FA would disconnect the session.
  • Fixed issue where terminal command script configured in the "Before open" section of the entry events was not executed before closing an SSH session.
  • Fixed RDM failing to connect when DVLS requires MFA.
  • Fixed synchronizer failure when an entry in the current vault uses the CURRENT_CLIPBOARD variable.
Devolutions Launcher 2026.1.23.026 mai 2026
Fonctionnalités
  • Added automatic recovery from corrupt offline files.
  • Added SSMS 21 and SSMS 22 default paths for SQL Server Management Studio entries.
  • Improved error message details when a PowerShell session fails to launch.
  • Removed non-user fields from X.509 credential settings.
Corrections
  • Fixed a security vulnerability in OpenMcdf.
  • Fixed Applications assignment opening in a different UI window.
  • Fixed context menu duplication issue in the filter dialog.
  • Fixed dialogs to respect the top-most state of the owner window.
  • Fixed display issue at non-default scaling on the background services page.
  • Fixed Forbidden Passwords from shared sources not being taken into account in the password generator.
  • Fixed infinite loading indicator when running synchronizers.
  • Fixed LastPass single sign-on error caused by mismatching username in JWT.
  • Fixed LastPass single sign-on issue for non-PKCE modes.
  • Fixed template display mode being lost during NetBox sync.
  • Fixed the notification tray not showing prompts.
  • Fixed typing macro not firing in SSH terminal.
  • Potential fix for SSH Terminal crash with 'Disconnect action' at 'Reconnect'.
Devolutions Server and Console 2026.1.19.021 mai 2026
Fonctionnalités

Server

  • Core - Added audit logging for Send Copy actions so administrators can track who shared entries and with whom.
  • Core - Hardened the authorization cache key to prevent any future cache-poisoning regression (follow-up to CVE-2026-1768).
  • Core - Improved authentication security to prevent external-provider sessions from bypassing password authentication under a different login method.
  • Core - Improved Active Directory user creation performance.
  • PAM - Added an option to skip TLS validation for the Windows Provider.
  • Web - Added Command key support for multi-selection in the web interface, allowing Mac users to extend selections with Cmd-click.

Console

  • Made minor updates.
Corrections

Server

  • CVE-2026-5171 Core - Fixed an issue where users without Activity Logs permission could still retrieve entry logs through the API.
  • CVE-2026-7325 PAM - Fixed an LDAP coercion issue that could force DVLS to authenticate against a malicious LDAP server.
  • CVE-2026-8477 Core - Fixed a security issue where sealed entries could be accessed through the partial sensitive-data endpoint without triggering unseal notifications.
  • CVE-2026-9047 Core - Fixed an issue where adding an additional MFA factor could remove an existing MFA key.
  • CVE-2026-9223 Core - Fixed a missing permission check that could allow users to create a new vault when importing an .rdx file referencing a non-existent vault.
  • CVE-2026-9224 Core - Fixed an issue where Active Directory accounts could modify their own profile data through the API despite UI restrictions.
  • CVE-2026-9245 Core - Fixed an open redirect vulnerability during external OAuth sign-in failures or cancellations.
  • CVE-2026-9246 Core - Fixed an issue where handbook content and attachment metadata from sealed entries could be accessed without following the unseal workflow.
  • CVE-2026-9247 Core - Fixed an issue where sealed credentials could be unsealed in another DVLS instance without notifying administrators, and improved handling of linked sealed credentials after import.
  • CVE-2026-9248 Core - Fixed an issue where duplicating a connection could copy handbooks and attachments from entries the user could not access.
  • CVE-2026-9249 Core - Fixed a password change bypass that allowed users to change passwords without providing the previous password.
  • CVE-2026-9251 Core - Fixed an issue where non-admin users could bypass the Pending Approval flow by changing an entry's status.
  • Core - Fixed a NullReferenceException in the notification processing service that could leave notifications stuck in an unprocessed state.
  • Core - Fixed an issue where Linked (External) credentials were not saved correctly on SSH entries linked to an SSH Key.
  • Core - Fixed attachments being lost when moving an entry to another vault.
  • Core - Fixed folder duplication so sub-entries are duplicated along with the parent folder.
  • Web - Fixed a TypeError when opening the Advanced Search dialog as a user without a User Vault.
Devolutions Launcher 2026.1.22.09 mai 2026
Fonctionnalités
  • Added a group policy to control the visibility of the 'Copy to YubiKey' option.
  • Added convert action for deprecated embedded credentials plus quick access through overview warning.
  • Excluded PAM vaults from secure message vault selection.
  • The SSH terminal compact display now remembers the last selected folder between sessions.
  • Updated Netwrix Password Secure integration for the 2026 version.
Corrections
  • Fixed a possible login issue with 1Password.
  • Fixed a potential error with custom folders in favorites.
  • Fixed an issue where system proxy mode "No Proxy" silently bypasses Devolutions Gateway.
  • Fixed crash for missing session type in NetBox synchronization.
  • Fixed crash when copying a password with missing source IDs in Hub data sources.
  • Fixed duplicate built-in PAM providers appearing in the Add Provider list.
  • Fixed filter prompt not appearing when using the shortcut.
  • Fixed freeze issue when the DVLS pre-authentication proxy fails.
  • Fixed freeze when canceling the Azure VMs sync login.
  • Fixed password list items requiring an item selection when opening history from an item.
  • Fixed performance issues when filtering entries and when importing large .rdm files.
  • Fixed possible crash when loading the cache.
  • Fixed SSH entries not supporting certain PuTTY extensions.
  • Fixed SSH sessions not being able to scroll up when using Codex or BYOBU.
  • Fixed Tasks no longer showing up for SQLite data sources.
  • Fixed templates with "prompt with list" credentials not loading the prompted folder.
  • Fixed the Zoho Vault credential integration and added region selection and CAPTCHA support.
Devolutions Server and Console 2026.1.16.05 mai 2026
Fonctionnalités

Server

  • CVE-2026-5146 Core - Closed a security gap allowing notification actions without authentication.

Console

  • Core - Added a support package generator to quickly collect diagnostics and configuration for faster issue resolution.
Corrections

Server

  • Core - Fixed a configuration error causing app settings to fail loading.
  • Core - Fixed admins receiving expiration alerts for other users' vault items.
  • Core - Fixed an issue where deleting a user could remove all users from the list.
  • Core - Fixed incorrect backup failure alerts and cleanup issues on Linux/Docker.
  • Core - Fixed unreliable installation of IIS ASP.NET Core Module on new Windows Server setups.
  • PAM - Fixed visibility selector closing too early when creating a new vault.
  • Web - Fixed "Disable MFA" dialog not closing after confirmation.
  • Web - Fixed default authentication method being ignored in Domain mode.
  • Web - Fixed empty notification banners appearing across admin pages.
  • Web - Fixed error dialogs showing blank content instead of messages.
  • Web - Fixed incorrect warning when saving entries with compromised passwords.
  • Web - Fixed login page defaulting to Domain authentication when set to "None".
  • Web - Fixed reveal/copy actions targeting the wrong field after sorting entries.
  • Web - Fixed Security Dashboard crash when navigating after resolving ignored issues.
  • Web - Multiple UI improvements and fixes.
Devolutions Launcher 2026.1.20.01 mai 2026
Fonctionnalités
  • Added organizational unit (OU) support to the Netwrix Password Secure integration.
Corrections
  • Fixed Hub attachments not being viewable after moving an entry to a different vault.
  • Fixed log cleanup discrepancies that could occur when coming back online after offline mode.
  • Fixed possible freeze on startup when taskbar visibility setting is set to "Never".
  • Fixed synchronization when using inherited credentials in Hub data source.
  • Fixed various VMware entry types not working when custom attributes are configured.
Devolutions Server and Console 2026.1.15.028 avr. 2026
Fonctionnalités

Server

  • CVE-2026-6706 Core - Added missing authorization check to prevent unauthorized access to handbook pages.
  • Core - Renamed Read-Only and Restricted user types to Legacy and removed Read-Only from default user templates.
  • Web - Updated third-party dependencies to address security issues, including a reported lodash vulnerability.

Console

  • Made minor updates.
Corrections

Server

  • Core - Allowed CyberArk entries to be saved without a username when using OIDC authentication.
  • Core - Fixed the Buy a License flow so licenses can be purchased and retrieved properly.
  • Core - Prevented permission set changes from being lost when saving after navigation.
  • Core - Resolved issue preventing administrators from removing user subscriptions.
  • Web - Ensured Reset Password prompt appears above Emergency Login prompt.
  • Web - Fixed Hide/Reveal behavior on sensitive fields after table sorting.
  • Web - Hid unsupported System Dashboard options in Customize Layout dialog for restricted vaults.
Devolutions Launcher 2026.1.19.023 avr. 2026
Fonctionnalités
  • Added SSO mode support to LastPass credential entries.
  • Improved the SSH embedded session so that toggling off SFTP also hides the file transfer window.
Corrections
  • Fixed 1Password SSO login issue when using non-default domains.
  • Fixed an issue where clearing the cache on close did not always work for website entries.
  • Fixed an issue where SSH KeyAgent did not always detect user vault keys when started at application launch.
  • Fixed CyberArk sessions not being saved to connection history.
  • Fixed dynamic credentials not working when used in templates.
  • Fixed issue with resolving the credentials of a synchronizer in Hub data sources.
  • Fixed password generator behavior when the same character was added to both the include and exclude lists.
  • Fixed RDP display scaling for custom Windows DPI settings.
Devolutions Gateway 2026.1.2.022 avr. 2026
Fonctionnalités
  • Service - The Gateway and Agent now support automated and scheduled Agent self-updates. Administrators can query update status and configure update schedules via new API endpoints.
Corrections
  • Service - Fixed a startup failure on Windows Server 2016 caused by a missing Windows Error Reporting API; the service now starts correctly on all supported Windows versions.
  • Service - Fixed missing disk space metrics in the heartbeat response when the recording directory has not yet been created.
  • Service - Fixed silent shadow recording failures (close code 4002) that produced no log output; warning logs are now emitted on all internal error paths.
  • Service - Fixed systemd startup failures on RHEL/Rocky Linux and improved RPM/DEB package lifecycle handling (correct enable/restart/disable behavior on install, upgrade, and removal).
Devolutions Server and Console 2026.1.14.015 avr. 2026
Fonctionnalités

Server

  • Core - Added option for admins to reset a user's dashboard layout.
  • Core - Improved LDAP group handling to support users with over 1,000 groups.
  • PAM - Improved loading speed of Azure AD groups and user auto-creation.
  • Web - Session names now show the connection name instead of the host name for better consistency.

Console

  • Made minor updates.
Corrections

Server

  • Core - Fixed error preventing MFA settings from being saved in user administration.
  • Core - Fixed false nightly "user modified" alerts during directory sync (Entra ID, AD, Okta, PingOne).
  • Core - Fixed Linux issue where access URL didn't update after setting a custom domain.
  • Core - Fixed login failure after upgrade caused by improperly migrated security key data.
  • Core - Fixed login issue for contractor users when Devolutions authentication was disabled.
  • Core - Fixed MFA policy bypass allowing users to delete their own MFA methods.
  • Core - Fixed unintended default vault access granted to imported domain users.
  • RestAPI - Fixed sort order parameter not applying correctly in vault endpoint.
  • RestAPI - Fixed vault filter to correctly return Infrastructure vaults.
  • Web - Fixed authentication filter not resetting properly in Users list.
  • Web - Fixed error when clicking info icon in Entra ID configuration.
  • Web - Fixed Linux issue causing repeated dashboard widget duplication.
  • Web - Multiple UI fixes and improvements.
Devolutions Launcher 2026.1.18.013 avr. 2026
Fonctionnalités
  • Deprecated the PAM dashboard entry type.
  • Added dynamic credential linking for Docker SSH key sessions.
  • Added support for direct keyboard macro injection in VNC and derivative sessions.
  • Improved batch edit image color.
Corrections
  • Fixed 1Password login issue where an invalid token caused too many requests to be sent.
  • Fixed 1Password vaults failing to load when macOS access restrictions are configured.
  • Fixed a null error in custom PowerShell reports.
  • Fixed a potential crash on application startup.
  • Fixed a potential crash related to temporary access requests.
  • Fixed active directory only showing the lastname when assigning AD security groups.
  • Fixed app proxy blocking background operations when the user is already authenticated.
  • Fixed drag and drop of folders from remote to local not always working with certain operating systems with SFTP panel opened in SSH terminal entries.
  • Fixed Elevate Shell incorrectly showing a timeout prompt on sessions that don't require passwords.
  • Fixed import license issue when in offline mode.
  • Fixed issue where launching an external web browser session using the system default would not take into account settings like incognito mode.
  • Fixed issue with two factor authentication with SSH terminal entry towards a Linux host.
  • Fixed keys incorrectly activating during terminal scrollback reset.
  • Fixed last focused tab not always being restored when the dashboard is not present.
  • Fixed Linked (External vault) credential selection incorrectly showing PAM vaults.
  • Fixed multiple 1Password issues.
  • Fixed OpenVPN entries incorrectly using the UDP protocol.
  • Fixed optional check-out mode not requiring check-out when editing the properties of an entry that is checked-out by someone else (when multi check-out is enabled).
  • Fixed possible duplicate entries in user/global vault.
  • Fixed possible issue where user overrides were not saved.
  • Fixed potential error when changing the application theme while an RDP session is open.
  • Fixed RDM freezing after clipboard operations in the terminal.
  • Fixed issue where the refresh button sometimes disappears.
  • Fixed removing a folder from favorites not properly removing the folder itself.
  • Fixed SonicWall NetExtender compatibility issues with version 10.3.4 and later.
  • Fixed SSH connections failing due to an unsupported MAC algorithm.
  • Fixed system permissions given to a regular user not being taken into account on Hub data source.
  • Fixed the permissions report displaying credentials in the session section.
  • Fixed unlock not working in a locked vault.
  • Fixed user management window automatically re-opening when launching RDM if it was opened before closing.
  • Fixed vault selection dropdown not responding to enter and arrow keys.
Devolutions Gateway 2026.1.1.02 avr. 2026
Fonctionnalités
  • Installer - Added German language support.
  • Installer - Certificates that fail validation are now shown with a warning icon instead of being silently hidden from the list.
  • Service - Credentials stored in memory are now encrypted at rest, protecting against exposure in memory dumps.
  • Service - Reduced log noise: a missing recording storage disk is now only reported once at warning level instead of repeatedly.
  • Service - Session recordings now use periodic key frames for improved seek performance during playback.
Corrections
  • Installer - Fixed an issue where semi-colons in certain configuration values could cause installation failures.
  • Service - Fixed an issue where certain service sub-commands were not recognized correctly.
  • Service - Fixed recording storage space reporting for network drives and UNC paths on Windows.
  • Service - Fixed recording storage space reporting for network file systems (NFS, Samba) on Linux and macOS.
  • Service - Fixed RPM package installing web application files under incorrect directory names.
  • Service - Fixed session recording playback failing with a "media could not be loaded" error.
  • Service - Fixed the Debian package incorrectly declaring a minimum system library version, preventing installation on some Linux distributions.
  • Service - Fixed video playback freezing during live session shadowing after brief recording pauses.
Devolutions Server and Console 2026.1.12.01 avr. 2026
Fonctionnalités

Server

  • Core
    • Added dashboard layout reset capability allowing administrators to reset a user's corrupted or misconfigured dashboard layout back to defaults.
Corrections

Server

  • Core
    • Fixed a security issue where MFA check could be bypassed when Emergency Code authentication was disabled.
    • Fixed an issue where OAuth session reuse could allow user impersonation, including administrators.
    • Fixed a security issue where MFA could be bypassed using an alternate authentication cookie.
    • Fixed an issue allowing users to remove their own MFA despite enforced restrictions.
    • Fixed an issue where users with management permissions could access other users' MFA secrets.
    • Fixed an issue where the gateway health check could be exploited for server-side request forgery (SSRF).
    • Fixed a regression where Microsoft User synchronization failed with an error reading 'UserCleanupDelta'.
    • Fixed an issue where approving temporary access requests did not work when only groups were set as approvers.
    • Fixed an issue where the contractor welcome email redirect did not work if the user was already logged in.
    • Fixed KeePass XML import incorrectly creating Legacy Website entries instead of the correct entry type.
    • Fixed Public API path query parameter filtering to work correctly with encoded URLs and nested paths.
    • Fixed the scheduler service crashing when custom log retention policy configuration contained invalid data.
  • Gateway
    • Fixed a server-side request forgery vulnerability in the gateway health check route.
    • Fixed an issue where new vaults could not be selected when changing the member filter in a gateway farm.
    • Fixed session recording not working when the session does not connect through a gateway.
    • Fixed the gateway going offline when a connection to a session fails due to a Virtual Gateway rule or other reason.
  • Web
    • Fixed a regression where the "All vault" button in the search stopped working.
    • Fixed an issue where Domain/AD users could not be added by browsing and selecting them.
    • Fixed normal users receiving an "Unable to save" error in the customize dashboard layout when a default dashboard exists.
    • Fixed the credit card edit component missing a reveal sensitive data button.
    • Fixed the entry security analyzer where the "Pwned" password filter was not working.
    • Fixed the TOTP window display being broken.

Console

  • Core
    • Fixed a regression where SQL-to-DVLS migration silently failed to decrypt User Vault (private) entries, causing users to see empty vaults after migration.
Devolutions Launcher 2026.1.16.030 mars 2026
Fonctionnalités
  • Added clipboard monitoring support for TeamViewer secure copy actions.
  • Added possibility to hide the download section of an SSH entry that has the SFTP tab activated.
  • Improved profiler traces to help identify performance issues.
  • Deprecated: Disabled hub personal creation in RDM.
Corrections
  • Fixed a regression where passwords could appear in plain text when using Post-login commands in SSH Terminal.
  • Fixed "Copy to Yubikey" menu item can cause high idle CPU usage in RDS environments.
  • Fixed "Is vault owner" not updating in RDM when vault permissions change in Hub web client.
  • Fixed issues related to the "Use this computer's credentials as the application password" setting.
  • Fixed potential edge session freezing the application.
  • Fixed potential issue when a theme change happens while Windows is locked.
  • Fixed potential RDP freeze on disconnect.
  • Fixed Serial port entry causing RDM to crash when closing the session.
  • Fixed small input delay in SSH entry.
  • Fixed some key presses interfering with scrollback in SSH entry when they should not.
  • Fixed some system permissions not working when on a Hub data source.
  • Fixed SSH key decryption bug with MAC ciphers (like chacha-poly).
  • Fixed user management window automatically re-opening when launching RDM if it was opened before closing.
Devolutions Launcher 2026.1.15.024 mars 2026
Fonctionnalités
  • Added a credential injection option to gateway security settings.
  • Added a sign-out button to the Entra ID console.
  • Added an option to allow empty DNS entries for WireGuard split tunneling scenarios.
  • Added option to force a fresh browser cache in incognito mode when launching the same entry multiple times.
  • Added two-factor authentication support for ISL AlwaysOn sessions.
  • Hub data sources now falls back to the user vault when no shared vaults are available.
  • Improved most recently used (MRU) connection list and connection override behavior.
  • Improved the local file explorer context menu with additional actions.
Corrections
  • Fixed 'Always ask for password' not working correctly for Password Depot entries.
  • Fixed a cache conflict that could cause browser-based session types to fail.
  • Fixed a possible crash when refreshing your entries.
  • Fixed a refresh issue that could occur after moving entries between vaults.
  • Fixed a sign-in issue with 1Password SSO where the authentication redirect token could be missing.
  • Fixed an issue where tools were available in a credential entry's dashboard when switching between session and credential type entries.
  • Fixed Batch Edit not properly refreshing VPN mode options when the VPN type is changed.
  • Fixed entering name of VM doesn't work with 'Always prompt for VM Name/ID'.
  • Fixed folder template group not being preserved on Hub data sources.
  • Fixed Hub data sources to resolve variables in linked host names.
  • Fixed issue that could cause duplicate files in the local SFTP explorer.
  • Fixed keyboard shortcuts not working in Default mode.
  • Fixed license detection on first login to a new DVLS.
  • Fixed local file explorer actions being unavailable when no file is selected.
  • Fixed RDP plugin paths having an unintended leading space.
  • Fixed secure gateway behavior inconsistencies between Chrome and Edge, and fixed Local mode for secure gateway SSH tunnels.
  • Fixed the host field being disabled when adding a new Hub Business data source.
Devolutions Server and Console 2026.1.11.019 mars 2026
Fonctionnalités

Server

  • Core - Added "Show Release News" preference to control release notification visibility.
  • Core - Free License users now appear disabled with a clear visual indicator to explain login restriction.
  • Core - Renamed "System Dashboard" to "Administration Dashboard" for clearer terminology.
  • Gateway - Added update notification to System Dashboard.

Console

  • Core - Hide certificate passwords when updating Gateway certificates.
Corrections

Server

  • Core - Fixed "Allow API Key" setting not persisting after save.
  • Core - Fixed "Apply Least Permissions" failing when permissions were preconfigured.
  • Core - Fixed "Unable to save" error when users customize dashboards with a default dashboard set.
  • Core - Fixed clipboard restrictions not applying in RDP web sessions.
  • Core - Fixed contractor users unable to launch RDP sessions via permalink.
  • Core - Fixed error when running Last Usage Logs report for regular users.
  • Core - Fixed inability to update password generator templates.
  • Core - Fixed inability to view inherited OTP codes from root.
  • Core - Fixed intermittent dashboard widget reordering not applying.
  • Core - Fixed missing activity logs for User Group restore and delete actions.
  • Core - Fixed new users not being enabled by default when created.
  • Core - Fixed performance issues with Conditional Access Policies enabled.
  • Core - Fixed session termination redirecting incorrectly in Active Sessions view.
  • Core - Fixed user edits unintentionally removing assigned licenses.
  • Core - Fixed vault permissions appearing disabled for non-admin users.
  • Core - Resolved SQL collation issues during database and web backups.
  • Gateway - Fixed advanced domain settings not saving.
  • Gateway - Fixed drain mode and scan option issues in Gateway farms.
  • Gateway - Fixed inability to terminate sessions using credential injection.
  • Gateway - Fixed session launch failures with inherited Gateway Rule Sets.
  • PAM - Fixed duplicated parent folders during account import.
  • PAM - Fixed incorrect error title on recurrent SSH key scan failure.
  • PAM - Fixed missing out-of-sync icon for SSH key accounts.
  • PAM - Fixed module admins unable to see external vaults during import.
  • PAM - Fixed PAM logs and rotation reports stuck loading on refresh.
  • PAM - Fixed SSH checkout approval error with "Yes, unless it's JIT" option.
  • PAM - Fixed unauthorized users appearing in checkout approver list.
  • PAM - Restored custom fields visibility in connection overview.
  • Web - Fixed "Access Denied" error for non-admin session launches with credential injection.
  • Web - Fixed PAM checkout redirect causing 404 error.
  • Web - Fixed Remote PowerShell entries not launching in web client.

Console

  • Core - Fixed error when editing Certificate Store locations.
  • Gateway - Fixed inability to add certificates when editing Gateway.
Devolutions Launcher 2026.1.14.016 mars 2026
Fonctionnalités
  • Added multi-session support for AI Assistant.
Corrections
  • Fixed a possible loss of user specific settings on after creating an instance of a DVLS data source and connecting to it.
  • Fixed Active Directory Dashboard duplicating group membership when editing a group.
  • Fixed issue where Typing Macros executed through "Execute in the current tab page" run several times.
  • Fixed issue where unlocking RDM could lead to everything being disabled and unusable until a force refresh.
  • Fixed issue with opening multiple embedded Windows Terminal entries.
  • Fixed possible crash after modifying data sources.
Devolutions Launcher 2026.1.12.012 mars 2026
Fonctionnalités
  • Added export functionality to the System Diagnostics and About dialog list views.
  • Improved error handling when importing an RDD file during the onboarding process.
  • Updated the default image for Netwrix Password Secure entries.
Corrections
  • Fixed a crash in Netwrix Password Secure when the window was already closed.
  • Fixed a policy categorization issue in the Group Policy administrative template.
  • Fixed a potential freeze when opening connections.
  • Fixed a regression where importing .rdm files would fail.
  • Fixed an issue with node loading when launching the application.
  • Fixed and improved certificate sending via Devolutions Send.
  • Fixed embedded applications launched via Command Line Tool entries not always displaying at the correct size when used through a remote RDM instance.
  • Fixed loading errors for Hub Business entries with malformed data.
  • Fixed missing permission validation for editing the system dashboard.
  • Fixed the {DELAY} command handling in terminal typing macros.
  • Fixed the empty folder's documentation tab not opening in a separate window when double-clicking.
  • Fixed the Multivault Advanced Search using OR instead of AND as the logical operator for DVLS data sources.
Devolutions Launcher 2026.1.11.011 mars 2026
Fonctionnalités
  • Added a Just-In-Time (JIT) authorization tab for Hub AD/EntraID PAM entries.
  • Added Active Directory and Entra ID group management support.
  • Added auto-mode to the performance profiler.
  • Added configurable wait time before attempting to embed an application launched by the Command Line Tool entry.
  • Added elapsed time display to the system information view.
  • Added Group Policy settings to control visibility of AI features and contact support options.
  • Added missing PAM usage policies validation when going through the PAM dashboard.
  • Added persistence of the AI assistant chat session between application restarts.
  • Extended the HideDevolutionsContactSupport Group Policy to also hide the survey button.
  • Improved favorites tab loading performance.
  • Improved the data migration progress message to display in the status bar.
  • Improved the resize handle area on forms to make window resizing easier.
Corrections
  • Fixed a crash when creating a documentation page in a Hub data source.
  • Fixed an issue preventing custom widget display before a pending database upgrade is applied.
  • Fixed an issue where viewing a password conflicted with the append OTP to username feature.
  • Fixed Docker management entries not saving correctly with inherited credentials; added multi-authentication support.
  • Fixed inherited PAM permissions not being correctly resolved.
  • Fixed Jump Host connection not working.
  • Fixed keyboard shortcuts (Enter, Ctrl+Backspace, and others) not working correctly in some forms.
  • Fixed multiple memory leaks that could affect performance over time.
  • Fixed multiple prompts appearing when copying a one-time password (OTP).
  • Fixed possible freeze (deadlock) at start of RDM and/or vault refresh.
  • Fixed SQL Server 2014 compatibility with database upgrade operations.
  • Fixed the scrollbar not appearing in the vault picker.
  • Fixed the splash screen not hiding when prompted to unlock a vault at startup.
  • Fixed undocked dashboard windows preventing the tabbed view from being properly closed.
  • Fixed virtual gateways appearing twice in the Hub data source list.
  • Fixed VPN connections sometimes showing no name in the opened connections list.
Devolutions Server and Console 2026.1.7.010 mars 2026
Fonctionnalités

Server

  • Core - Added an option to hide the domain login method when domain SSO is enabled.
  • Core - Dynamic IP Lists are now generated by the server so they work correctly in the web interface and all clients.
  • Core - Expired entry lists and scheduled reports now display the full folder path for better context.
  • Gateway - In RDM, the Gateway section is only available for vaults with Gateway access.

Console

  • Added SQL database compatibility level verification during updates to prevent upgrade failures.
Corrections

Server

  • Core - Fixed path filtering behavior in the Public API, including support for empty paths returning root entries.
  • Core - Fixed a crash when editing unsupported entry types.
  • Core - Fixed a failure when moving entries between vaults with folders sharing the same name in RDM.
  • Core - Fixed activity logs showing identical active time and duration values when switching tabs.
  • Core - Fixed an incorrect message indicating DVLS would revert to the free version after deleting a license.
  • Core - Fixed errors triggered by the "Buy now" button in the licenses section.
  • Core - Fixed missing activity log events when deleting or restoring user groups.
  • Gateway - Gateway-managed sessions from user vaults now correctly display the user's identity.
  • PAM - Fixed an empty approver list in the checkout approval dialog for certain SSH account configurations.
  • PAM - Fixed an issue where the default Gateway was not saved when enabling Gateway usage on a PAM provider.
  • PAM - Fixed domain PAM provider connection tests incorrectly falling back to the parent domain.
  • PAM - Fixed missing password reset after failed JIT elevation for non-provisioning accounts.
  • PAM - Fixed OTP prompt appearing for brokering-only PAM accounts.
  • PAM - Fixed vault owners missing from checkout request approver lists.
  • PAM - Fixed visual issues in the propagation template interface.
  • Web - Fixed a blank tree view that appeared when editing entries near the bottom of the scroll position.
  • Web - Fixed a Content Security Policy issue preventing RDP connections in the web client.
  • Web - Fixed an error when saving user vault entries for accounts without a user vault.
  • Web - Fixed live session recordings showing an empty dialog in the web client.
  • Web - Fixed SSH session recordings not opening in the web interface.
  • Web - Fixed the "Reveal password" button failing when creating a Password List entry.

Console

  • Fixed an installation failure during SQL Server Express setup caused by generated passwords containing single quotes.
Devolutions Launcher 2026.1.10.04 mars 2026
Fonctionnalités
  • Added AI configuration dialog for managing AI assistant settings.
  • Added PowerShell script execution support through Devolutions Gateway.
  • Allow RDM to fill a Yubikey slot with a checked out PAM password.
  • Improved PAM dashboard loading performance.
Corrections
  • Fixed 'View entries' permission toggle not appearing enabled in vault settings.
  • Fixed an issue when opening files from the tabbed view.
  • Fixed crash when closing a serial port entry session.
  • Fixed custom system proxy settings not being applied to DVLS and certain Hub data source requests.
  • Fixed display issues for icon buttons embedded in text boxes.
  • Fixed Docker entries failing to load embedded SSH keys.
  • Fixed entry search in the MCP server for SQLite data sources.
  • Fixed file contents not saving when using File > Save in the text editor entry.
  • Fixed Hub data source not always resolving user principal names correctly.
  • Fixed Import multiple vault not working in Hub data source.
  • Fixed macros/scripts/tools entries not working when launched from an opened entry's embedded tab's right click menu.
  • Fixed password encryption issue with empty passwords set on attachments.
  • Fixed status bar persisting under certain conditions in website entries.
  • Fixed tag ordering issue in the overview.
  • Fixed variable resolving for Alarm, Door Code, and Other entry types.
Devolutions Launcher 2026.1.9.0Version majeure3 mars 2026
Fonctionnalités
  • New features
    • Added a way for an administrator to create a preset dashboard for their users.
    • Added ControlR entry type.
    • Added Docker management console entry.
    • Added domain registrar as a new information entry type.
    • Added GetScreen entry type.
    • Added JWT credential entry type.
    • Added local recording support for all free data sources.
    • Added PGP credential entry type.
    • Added PowerShell Universal entry type.
    • Added UniGetUI as an available application tool.
  • Improvements
    • Deprecated Cryptocurrency cold storage entry type is deprecated.
    • Deprecated Deprecated Spiceworks import - Use the generic CSV importer instead.
    • Deprecated Deprecated spiceworks tool.
    • Deprecated Deprecated TrueKey entry.
    • Deprecated Replaced Winget dashboard with UniGetUI.
    • Added 'show advanced columns' to VMWare dashboard in SOAP API mode.
    • Added "Hide toolstrip" option to Apple Remote Desktop entry settings.
    • Added "Linked (External vault)" mode to OTP selection in entry properties.
    • Added "Open in background" option in the advanced section of entries.
    • Added "Prompt on connection" option to linked VPN.
    • Added "Search all" option in Advanced Search custom fields to search across all custom field values at once.
    • Added /ConfigPath command-line switch to specify a custom configuration directory for RDM.
    • Added a Group Policy setting to control automatic logoff when disconnecting an RDP session.
    • Added a link for external login in the embdded Devolutions login.
    • Added a new Markdown editor with preview mode and syntax highlighting that adapts to light and dark themes.
    • Added a PAM feature discovery screen when PAM is not yet configured.
    • Added a recording gateway setting to connection entries.
    • Added a setting to the VMWare synchronizer to exclude hosts by name.
    • Added a visual security indicator on embedded sessions when credential injection is active.
    • Added ability to edit risk levels for Active Directory and Entra ID security groups and roles in PAM providers.
    • Added AD authentication mode for OneIdentity.
    • Added additional Active Directory user edit fields.
    • Added API key support to credential selection for AI assistant entry.
    • Added better messaging support when DVLS is in maintenance mode.
    • Added certificate file support to SSH key credentials and improved support in SSH terminal entries.
    • Added Copy email to default credential entry overview.
    • Added Copy OTP action in the after connection events.
    • Added Copy to Clipboard credential events for After Open actions.
    • Added disconnect action inheritance for terminal entries.
    • Added disconnect button availability for additional connection types.
    • Added documentation search button to the main filter menu.
    • Added DPI awareness support for RDP external connections (mstsc).
    • Added escape key support to close the vault selector dialog.
    • Added file size column to file explorer entries.
    • Added filtering and role support to NetBox synchronization.
    • Added first implementation of Devolutions Agent DVC to RDM.
    • Added gateway session termination when the PAM account is checked in.
    • Added group membership support to Azure PIM entry.
    • Added group policy option to enforce 'Show folder details as selected' setting.
    • Added host field source setting to the VMware synchronizer.
    • Added HP iLO (Native) support for Devolutions Gateway.
    • Added Internet Protocol to SCP properties.
    • Added linked credential selection for the API key in the AI assistant.
    • Added live chat support button to the ribbon for quick access to customer support.
    • Added markdown document entry type.
    • Added max length to passphrase for Password Generator.
    • Added MCP client support in AI Assistant with OAuth authentication, file attachments, and drag-and-drop functionality.
    • Added MCP tools for creating, reading, updating, and deleting entry documentation.
    • Added multi-instance RDM mode for Now Agent Jump.
    • Added OIDC authentication support for CyberArk.
    • Added option to automatically switch to dashboard when closing a session.
    • Added PAM onboarding "Get started" experience.
    • Added Passwordstate integration to include MFA handling for APIs.
    • Added possibility to configure the default behavior for "Automatically check in PAM account when closing entry".
    • Added Proxmox as a new synchronizer option.
    • Added read-only and destructive operation indicators to AI assistant tools.
    • Added remote time zone support in entry logs for displaying activity in the remote machine's local time.
    • Added reset scrollback on keypress setting in terminal sessions.
    • Added reveal button for more fields in devo send.
    • Added security groups risk analysis for Hub Business data sources.
    • Added service principal authentication support to the Azure VM synchronizer.
    • Added single sign-on support to 1Password entries.
    • Added SSH support to OneIdentity entries.
    • Added support for AES192 and AES256 for SNMP.
    • Added support for custom OpenAI endpoints.
    • Added support for including the password as a variable in synchronizer configurations.
    • Added support for linked owner custom field variables (e.g., $LINKED_OWNER_CUSTOM_FIELD1$).
    • Added support for privileged accounts in Active Directory dashboard connections.
    • Added support for SSO in LastPass integration.
    • Added support for tag inheritance as a setting in the vault and system settings.
    • Added support for using CyberArk Connect with shared playlists.
    • Added tab group multi select by holding the Ctrl key.
    • Added tab title and tab color override to User/Local specific settings.
    • Added temporary access feature to PAM accounts.
    • Added terminal command macros to After Open and Before Close events.
    • Added the data-ciphers property to OpenVPN.
    • Added time-based color coding when viewing OTPs.
    • Added variable resolution support in PAM service for network, VPN, and host-based configurations.
    • Added web autofill security and navigation controls.
    • Allow to reuse the same cache between Web sessions when connecting via Gateway.
    • Changed default value of entry security settings to use inherited values.
    • Changed the default data source login behavior to use the embedded browser instead of external.
    • Changed the vault dropdown to remember the last selected tab instead of defaulting to "All Vaults".
    • Disabled password-related features when password saving is turned off.
    • Implemented GitHub Copilot SDK integration to AI Assistant.
    • Improved "One Identity Safeguard for Privileged Passwords" entry to support Privileged Passwords and Privileged Sessions - The entry was also renamed to "One Identity Safeguard".
    • Improved "view password" behavior on attachments to look at the attachment permissions instead of the main entry permissions.
    • Improved AI assistant interface with additional text formatting options.
    • Improved AI Assistant layout with better model name display, text wrapping, and screenshot button availability.
    • Improved clipboard behavior for more reliable password clearing.
    • Improved double-click behavior to navigate and launch entries by default in multi vault and advanced search results.
    • Improved error handling for gateway permission failures.
    • Improved error handling for Microsoft SQL Server connections.
    • Improved error handling when CSV file cannot be read.
    • Improved error messaging when creating a Hub with an invalid or already-taken name.
    • Improved IP list filtering functionality.
    • Improved license management interface and updated legacy key icon.
    • Improved offline mode reliability and error handling.
    • Improved OTP generation to automatically trim spaces from the secret key, preventing incorrect codes from being generated.
    • Improved performance when loading global and user vaults by loading them asynchronously.
    • Improved performance when switching between vaults.
    • Improved Proxmox to support adding new virtual machines.
    • Improved quick search user experience with better keyboard navigation.
    • Improved tag search functionality in quick search.
    • Improved the first launch experience: new installations now display quick connect buttons for RDP, SSH, VNC, ARD, and web connections when no entries exist.
    • Improved the onboarding experience with UI enhancements and added the ability to configure multiple Hub Business instances at once.
    • Improved the visual design of the AI Assistant.
    • Improved user experience for sealed entries in quick search.
    • Launching RDP as Undocked and Full Screen will now hide the taskbar and display the undocked menu.
    • Linked External vault now supported in SSH Terminal and SSH Port forward for SSH Key.
    • Merged advanced search and multi-vault search into one.
    • Optimized autofill element detection in WebView2 when only name or placeholder attributes are present.
    • Removed gateway selection from Quick Connect for Hub Personal data sources.
    • Renamed 2xclient connection type to Parallels Client.
    • Renamed Teradici PCoIP client add-on to HP Anyware PCoIP client.
    • Unified the terminology for "Keep tab opened on disconnect" for sessions and "Disconnect action" for SSH.
    • Updated application splash screen.
    • Updated Markdown viewer with syntax highlighting.
Corrections
  • Fixed keep in memory option for Delinea Secret Server "My account settings".
  • Fixed $MACRO_PASSWORD$ variable not working correctly in high security vaults on Devolutions Server.
  • Fixed a crash when disconnecting an AI Assistant session using the session menu.
  • Fixed a display glitch in the AI Assistant chat when using screenshots.
  • Fixed a LastPass DUO login failure when a linked device had no available two-factor authentication methods.
  • Fixed a refresh issue in the script dashboard.
  • Fixed a text highlighting issue in SSH sessions when scrolling.
  • Fixed actions not working in TN3270 and TN5250 terminals.
  • Fixed an issue where connections that do not support PAM credentials could be opened with a PAM credential.
  • Fixed an issue where credentials were not saved correctly in FortiClient connections.
  • Fixed an issue where Devolutions gateways were incorrectly fetched for Hub Personal data sources.
  • Fixed an issue where keys pressed while disconnected from an SSH entry were sent to the session after reconnecting.
  • Fixed an issue where PAM connections could be incorrectly checked in or marked as closed while still running.
  • Fixed an issue where some entry actions weren't working from the group dashboard.
  • Fixed an issue where SSH tunnels using the parent host would fail when in a folder containing variables.
  • Fixed an issue where the UPN username format was not applied correctly when using a PAM credential entry with a Hub data source.
  • Fixed an issue with Hyper-V entry filtering that broke virtual machine selection.
  • Fixed an issue with SOCKS5 connections when using an existing gateway tunnel.
  • Fixed an issue with the code editor showing incorrect modified state.
  • Fixed and issue where inherited credentials resolving could result in a crash.
  • Fixed automatic check in not working when using SSH Key Privileged account.
  • Fixed automatic synchronizers logging a close event even when they weren't opened.
  • Fixed certificate expiration date not properly removing time component when auto-populating from certificate.
  • Fixed check in issue when opening connections from PAM vault.
  • Fixed crash that occurred during LAPS password decryption.
  • Fixed default SSH template selection in PAM checkout settings.
  • Fixed dropdown selectors losing their selected value when switching tabs.
  • Fixed enter key behavior and translation issues in TLS Diagnostics window.
  • Fixed error after connecting to a Hub data source with a user that has no execute permission on at least 1 synchronizer in the active vault.
  • Fixed errors in Devolutions Send feature.
  • Fixed errors when connecting to a hub business free for the first time.
  • Fixed events macros causing RDM hangs when macros would be set to launch session.
  • Fixed gateways being loaded for data sources that don't support them.
  • Fixed Hub trial expiration notification to show on data source change.
  • Fixed issue where Hub PAM entries prompted for checkout even when checkout mode was disabled.
  • Fixed issue where PAM JIT provisioning accounts were not displaying passwords.
  • Fixed issue with Dashlane email MFA.
  • Fixed issue with duplicate user information history records.
  • Fixed issue with variable in data source username and log off data source.
  • Fixed issues with one-time password (OTP) variable resolution and credential interactions.
  • Fixed JIT account selection in PAM provider.
  • Fixed LAPS secret decryption method signature for compatibility with SSPI library.
  • Fixed non-default folder type templates not appearing when adding entries from templates.
  • Fixed null reference exceptions when closing the application.
  • Fixed offline backup behavior for Hub Personal data sources.
  • Fixed PAM features not being available when using a DVLS data source.
  • Fixed PAM providers not being added to PAM vault.
  • Fixed PAM SSH account checkout functionality.
  • Fixed possible application crash when double clicking a .rdx file.
  • Fixed possible issue closing entries over VPN.
  • Fixed potential memory leak caused by trayicons.
  • Fixed progress bar display in advanced search.
  • Fixed quick connect dashboard loading gateways too frequently.
  • Fixed SSH JIT template retrieval when no default template is configured.
  • Fixed styling and alignment issues for section separators.
  • Fixed TeamViewer connections to properly handle special characters in passwords.
  • Fixed template groups being visible in contexts where they are not supported.
  • Fixed the 'Open (Select Credentials)' action not working.
  • Fixed the About dialog for the Launcher.
  • Fixed the application language not loading correctly.
  • Fixed the script editor's syntax highlighting not updating when switching between light and dark themes.
  • Fixed transparency issue with the most recently used list.
  • Fixed View Password visual refreshing issue when OTP was Append/Prepended.
  • Fixed viewing credentials not working in secure vaults for DVLS.
  • Fixed virtual gateway connections to enforce server-side token validation.
Devolutions Server and Console 2026.1.6.0Version majeure3 mars 2026
Fonctionnalités

Server

  • New Features:
    • Core - Added custom vault dashboard widgets with drag-and-drop reordering.
    • Core - Added Just-in-Time (JiT) access for SSH (sudo) sessions.
    • Core - Added new Contractors account type with expiration date support.
    • Core - Added support for SSH key certificates in the web.
    • Core - Added vault priority sorting.
    • Core - Admins can create preset dashboards for users.
    • Core - Licenses can now be purchased directly within DVLS.
    • Core - Multiple Improved and fixed with the synchronizer where they was mismatch with RDM.
    • Core - Users can now request a trial directly from the application.
    • Core - Users can now request sudo access when requesting checkout.
    • Gateway - Added RDP credential injection for more secure session launches.
    • Gateway - Added traffic event logs to privileged session monitoring.
    • PAM - Added MongoDB provider support.
    • PAM - Added PowerShell session recording.
    • PAM - Added the ability to automatically terminate active sessions when a PAM account is checked in.
    • PAM - Added UI to assign and manage risk levels for roles.
  • Improvements:
    • Core - Added "Prompt on connection" support for linked VPN/SSH/Gateway sessions, matching the behavior already available for linked credentials.
    • Core - Added launch links on connections for quick session sharing.
    • Core - Added missing fields in the "Advanced" tab for SFTP connections.
    • Core - Added OTP support for linked external vaults.
    • Core - Added support for editing Delinea Secret Server entries directly within DVLS.
    • Core - Admins can set the default behavior for automatically checking in PAM accounts when closing entries.
    • Core - Corrected inaccurate syslog messages that reported successful logins incorrectly.
    • Core - Entra ID now enforces secret expiration with banner and email warnings.
    • Core - Entry security settings now use inherited values by default.
    • Core - Error reports now include connection type details.
    • Core - Improve Entry Security Analyzer report to include all relevant fields, matching the information already available in RDM.
    • Core - Improved license management, disabling a user now automatically removes their assigned licenses.
    • Core - Improved performance for access requests in RDM.
    • Core - Linked vaults can now point to entries in the same folder.
    • Core - Public API now supports CRUD operations for folders and vaults.
    • Core - Renamed Log Retention Policies to Database Retention Policies and added retention options for connection history, remote sessions, and traffic events.
    • Core - Simplified license assignment in data sources.
    • Core - Synchronizers now support scheduling by hour.
    • Core - Tags can now be used with inheritance rules.
    • Core - The public API now supports full CRUD operations for vaults, allowing administrators to create, read, update, and delete vaults programmatically.
    • Core - Users can now configure multiple MFA methods at once.
    • Gateway - Renamed "Virtual Gateway" to "Gateway ruleset".
    • Gateway - Sessions can now be recorded on a different gateway than the launch gateway.
    • Gateway - The Gateway Diagnostic window now displays whether Devolutions Agent is installed and running.
    • Gateway - The gateway list now automatically refreshes after an update request completes.
    • PAM - Added "Create folder" option when importing PAM accounts.
    • PAM - Added "Skip TLS validation" option in PowerShell provider settings.
    • PAM - Added "Workspace" as a supported application option in the PAM usage policies admin section.
    • PAM - Improved error message when no provider is specified on a PAM account.
    • PAM - Renamed "Scan" to "Account Discovery".
    • PAM - Users without a PAM license can now perform basic PAM operations, such as checking out PAM credentials, without requiring a full PAM license Assignment.
    • Web - Added a warning in the web interface when an OTP account name contains a colon (":"), consistent with existing behavior in RDM.
    • Web - Administrators can now set permissions on entry types that are not technically supported on the web.
    • Web - Users can now customize the "Add connection" favorites section.
    • Web Client - Multiple UI improvements.
    • Web Client - Updated dark theme.

Console

  • Improvements:
    • Core - Improved performance for static resource loading by enabling HTTP/2 support when anonymous authentication is configured in IIS.
    • Core - Renamed the "Stable" release channel to "Extended maintenance" in the console to better reflect its support lifecycle.
    • Gateway - Added a new System Certificate Store configuration key for Devolutions Gateway in the console.
Corrections

Server

  • Core - Fixed a regression where it was no longer possible to set a user as an administrator.
  • Core - Fixed a scheduler timeout error that could cause scheduled tasks to fail intermittently.
  • Core - Fixed an error occurring when too many vaults were present.
  • Core - Fixed an error that occurred when editing account login information on a deprecated entry type.
  • Core - Fixed an issue where exported logs from the DVLS Console were being cropped and truncated.
  • Core - Fixed an issue where forbidden passwords could still be saved in a password list entry.
  • Core - Fixed an issue where new Active Directory user accounts were not appearing in DVLS, preventing the auto-create on first login feature from Working correctly.
  • Core - Fixed an issue where OAuth token rejections were incorrectly returning HTTP 200 with an empty response instead of a proper error code.
  • Core - Fixed duplicate vault cards appearing on the dashboard.
  • Core - Fixed notification emails being sent in English for users configured in French.
  • Core - Fixed repeated migration attempts after SQL migration and server restart.
  • Gateway - Fixed a issue where clicking "Close" from the session kebab menu did not always close the session on the first attempt.
  • Gateway - Fixed a missing configuration option in the Web UI for allowing additional hosts through Devolutions Gateway.
  • Gateway - Fixed an inconsistency in how Gateway tunnels were configured and displayed between RDM and the Web UI.
  • Gateway - Fixed an issue where enabling vault-level security on a gateway prevented it from being used in gateway farms and PAM providers.
  • Gateway - Fixed an issue where virtual gateways were not automatically deleted when their associated physical gateway was removed, leaving orphaned entries that no longer functioned.
  • PAM - Fixed "Nobody" account appearing when "Ignore system users" was enabled.
  • PAM - Fixed a security issue where non-administrator users could view other users' PAM actions in the Privileged Access logs.
  • PAM - Fixed account discovery failure caused by circular security group membership.
  • PAM - Fixed an error that occurred when attempting to add a folder to a newly created PAM vault during the import process.
  • PAM - Fixed an issue where Domain Quick Scan was no longer working.
  • PAM - Fixed an issue where groups located in the Builtin organizational unit were not visible when selecting groups for JIT (Just-In-Time) elevation.
  • PAM - Fixed Local Windows scan failure when credentials were linked.
  • PAM - Fixed SSH scan failure when sudo was configured with NOPASSWORD.
  • Web - Fixed inconsistent rendering of secure notes set as Markdown across different platforms.
  • Web - Fixed the Notification Subscriptions filter not working correctly.
  • Web - Multiple UI fixes.

Console

  • Core - Fixed basic installation failure when a generated password contained a single quote (').
  • Gateway - Fixed an issue in the console where certificate configuration was cleared when editing a gateway, requiring users to re-enter the certificate.
Devolutions Gateway 2026.1.0.0Version majeure27 févr. 2026
Fonctionnalités
  • Service - Added options to use a dedicated certificate for CredSSP credential injection.
  • Service - Improved Gateway now auto-generates a self-signed certificate for CredSSP when no TLS certificate is configured.
  • Service - Improved real-time performance of session shadowing.
Devolutions Launcher 2025.3.32.026 févr. 2026
Fonctionnalités
  • Added Devolutions Gateway support to SSH PAM providers.
  • Improved double-click behavior in "all vaults" and advanced search to both navigate to folder and launch entries by default.
  • Improved how CyberArk session expiration is handled.
Corrections
  • Fixed 'Mandatory on JIT elavation' issues on a PAM SSH account's checkout.
  • Fixed 'Unable to connect to your data source' prompting after losing connection even when you switched to another data source.
  • Fixed $SESSION_ID$ returning wrong ID when PowerShell macro is executed from RDP session's context menu.
  • Fixed ALT + ASCII code combinations not producing any characters in SSH terminal.
  • Fixed connection loss that could occur when refreshing access requests.
  • Fixed empty credential names in Passbolt when using encrypted metadata.
  • Fixed error in Hub data source when starting an entry from the favorites tab while not in the vault of the entry.
  • Fixed error when creating new containers in Azure Blob Storage file explorers.
  • Fixed error when opening Teamviewer with a bad ID.
  • Fixed host variable resolution issue in website connections when using custom ports.
  • Fixed issue where a force refresh is needed to be able to see a PAM provisioner account's password in Hub data source.
  • Fixed issue where external RDP connections could fail due to missing a temp folder.
  • Fixed issues with SSPI module for SSH entry.
  • Fixed Jump sessions failing to launch.
  • Fixed loss of connection with the data source triggering resizing issues.
  • Fixed missing access rights when working in the User Vault.
  • Fixed remote services failing to load.
  • Fixed SSH account checkout not working correctly with JIT elevation.
  • Fixed SSH Key credentials stored in the User Vault not working correctly when used through inheritance.
  • Fixed SSH timeout of 300 seconds not being respected when the connection is really long to establish.
  • Fixed the Bitwarden synchronizer creating shortcuts on data sources that do not support them.
  • Fixed UPN username format not being applied correctly when using PAM credential entries.
  • Fixed VPN auto-close not correctly updating the connection's opened state.
Devolutions Gateway 2025.3.4.010 févr. 2026
Fonctionnalités
  • Installer - You can now allow downloading keys even when the certificate isn't trusted (useful in restricted/air-gapped environments).
  • Service - Added credential injection support for RDCleanPath.
  • Service - Added outbound HTTP/HTTPS/SOCKS4/SOCKS5 proxy configuration support.
  • Service - Added ARM64 Docker image support (run natively on ARM hosts).
  • Service - Reduce noisy logs: benign client disconnects are now logged as DEBUG instead of ERROR.
Corrections
  • Installer - Fixed the handling of certificate passwords containing single quotes.
  • Service - Fixed certificate store resolution error logging to include clearer failure details.
  • Service - Fixed Docker image build to correctly generate a self-signed TLS certificate.
  • Service - Fixed Linux container startup to honor the TCP_PORT environment variable.
Devolutions Server and Console 2025.3.15.09 févr. 2026
Fonctionnalités

Console

  • Made minor updates.
Corrections

Server

  • Security Fix: Core - Fixed sensitive credential exposure through API endpoints for users with View-only permissions.
  • Security Fix: Core - Enhanced database security by encrypting previously cleartext personal credentials storage.
  • Core - Fixed crash in Reports > Entry Diagnostic page.
  • Core - Fixed credential prompt appearing unexpectedly when sessions inherit credentials from parent folders.
  • Core - Fixed issue where MFA reset option was not working properly for user accounts.
  • Core - Fixed issue where some user vault entries were permanently lost when deleting a user and transferring their vault.
  • Gateway - Fixed PAM sessions remaining open in Gateway when PAM operations fail, preventing session accumulation.
  • Linux - Fixed error when configuring Active Directory authentication on Linux servers.
  • PAM - Fixed password reset not being triggered after importing Entra ID accounts.
  • Web - Fixed character encoding issues in Active Directory Console displaying special characters incorrectly.
  • Web - Fixed infinite resize loop causing flickering or grey screen when switching from Dynamic Resizing to Actual Size mode.
  • Web - Fixed tag autocomplete not filling in the rest of the tag name when selecting from dropdown suggestions.
  • Web - Fixed tree view crash.
Devolutions Launcher 2025.3.30.027 janv. 2026
Fonctionnalités
  • Added button in About page to copy version number to clipboard.
  • Added error clarifications for OneIdentity Safeguard when connection issues occur.
  • Improved error messaging when connecting to SSH terminal.
  • Improved Updater to notify users when required .NET runtime is missing.
  • Removed MFA prompt for unsupported data sources.
  • Removed need to input a character to enable pressing OK in the SSH interactive authentication prompt.
Corrections
  • Fixed caps lock key state does not toggle properly during VNC sessions.
  • Fixed copying version number from about page triggering clipboard timer.
  • Fixed FreeVNC cannot connect to Vino server with encryption enabled.
  • Fixed gateway settings not being saved in website entry's SSH VPN configuration.
  • Fixed issue in SSH entry where some special characters would not appear unless pressed multiple times.
  • Fixed issue where cloud backup option remained visible when unsupported.
  • Fixed issue where Hub provisioner just-in-time accounts could be checked out without selecting required groups.
  • Fixed locked status staying active after editing an entry.
  • Fixed password generation issues when password complexity is set to inherited.
  • Fixed script execution from command palette when using "allow open multiple connections" setting.
Devolutions Server and Console 2025.3.14.015 janv. 2026
Fonctionnalités

Server

  • Core - Added the ability to request a trial directly from the application.
  • Core - Added connection type information to error reports for better troubleshooting.
  • Core - Updated DUO MFA integration.

Console

  • Made minor updates.
Corrections

Server

  • (Security Fix) Core - Fixed SQL injection vulnerability in remote sessions API.
  • (Security Fix) Gateway - Fixed issue where virtual gateway deny IP and DNS rules are being bypassed using linked host entries in user vaults.
  • Core - Fixed issue where syslog timestamp format is invalid in certain locales, such as Finland.
  • Core - Fixed issue where vault filter is not being applied correctly in PAM recent activities scheduled reports.
  • Gateway - Fixed issue where variables are not being resolved in privileged session monitoring.
  • PAM - Fixed issue where password is being updated in the database even when scheduled reset fails on the target system.
  • PAM - Fixed issue where Windows local account scans are failing on non-English operating systems.
  • Web - Fixed issue where sessions are failing to launch from web interface when user-specific settings are disabled globally.
Devolutions Launcher 2025.3.29.08 janv. 2026
Fonctionnalités
  • Added checkout section to entries in Hub data sources.
  • Added possibility to force refresh in launcher.
  • Updated DUO client version.
Corrections
  • [Security Fix] Fixed an issue with Team Viewer password visibility.
  • Fixed alternate host prompt appearing twice for host entries.
  • Fixed an SSH terminal rendering issue where background colors were not correctly cleared during scrolling (BCE support), causing display artifacts in applications such as Vim.
  • Fixed clipboard encoding for VNC connections.
  • Fixed error 403 in Hub when trying to get Gateway health information.
  • Fixed error when exporting a custom report with duplicate columns.
  • Fixed gateway list to show only virtual gateways when force virtual mode is enabled.
  • Fixed interaction between disabling all macro/script/tools in availability and remote tools display.
  • Fixed issue with CTRL key getting stuck in SSH entry.
  • Fixed issue with escape function and keyboard mapping not working in SSH.
  • Fixed issue with SSH connections not working when using a password variable in post-login commands.
  • Fixed possible error when closing application during windows theme change.
  • Fixed possible issue when moving a documentation page in Hub.
  • Fixed potential FAIL_PROTOCOL_ERROR in SSH entries.
  • Fixed SSH interactive authentication prompts to remove confusing popup behavior.
  • Fixed SSH terminal issue with keyboard shortcuts.
  • Potential fix for out of memory error when theme changes.