Security & compliance
Upholding the highest standards to protect your data and ensure trust.
DEVO-2026-0012
Devolutions Server is affected by an improper access control vulnerability.
Affected Products
Change Log
Initial publication - 2026-05-12
6.9 Medium - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Improper access control in notification management endpoints
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation.
This issue affects Server: from 2026.1.6.0 through 2026.1.15.0, through 2025.3.19.0.
Affected Products
CVE(s)
CVE-2026-5146
Remediation and Workarounds
Upgrade to Devolutions Server 2026.1.16.0 or higher.
Upgrade to Devolutions Server 2025.3.20.0 or higher.