Junglewise Threat Intelligence

CVE-2026-15058: Devolutions Server IDOR in secure messages deletion endpoint

CVE-2026-15058 · Severity: info · CVSS 0 · Published 2026-07-14

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and privileged access, contains a security flaw in its messaging system. An authenticated user can delete secure messages belonging to other users by manipulating message identifiers. This could lead to the unauthorized removal of sensitive communications or audit trails within the organization.

Technical details

An improper authorization vulnerability (CWE-639) exists in the secure messages deletion endpoint of Devolutions Server. The root cause is a lack of server-side validation to ensure that the authenticated user requesting a deletion owns the message associated with the provided identifier. By supplying a direct object reference (ID) of a message belonging to another user, an attacker can successfully trigger its deletion. This vulnerability affects versions 2026.1.22 and earlier, as well as 2026.2.11 and earlier. Users should upgrade to versions 2026.1.23.0 or 2026.2.12.0 to remediate the issue.

Affected products

  • Devolutions Server 2026.1.22 and earlier, 2026.2.11 and earlier

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched: Fixed in 2026.1.23.0 and 2026.2.12.0

References