HAUPTMENÜ

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0012

Devolutions Server is affected by an improper access control vulnerability.

Affected Products

Devolutions Server
2026.1.6.0 through 2026.1.15.0
Devolutions Server
2025.3.19.0 and earlier

Change Log

Initial publication - 2026-05-12

6.9 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Improper access control in notification management endpoints

Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation.

This issue affects Server: from 2026.1.6.0 through 2026.1.15.0, through 2025.3.19.0.

Affected Products

CVE(s)

CVE-2026-5146

Remediation and Workarounds

Upgrade to Devolutions Server 2026.1.16.0 or higher.

Upgrade to Devolutions Server 2025.3.20.0 or higher.