Executive brief
Devolutions Server, a centralized platform for managing remote connections and privileged access, contains a security flaw in its messaging system. An authenticated user can delete secure messages belonging to other users by manipulating message identifiers. This could lead to the unauthorized removal of sensitive communications or audit trails within the organization.
Technical details
An improper authorization vulnerability (CWE-639) exists in the secure messages deletion endpoint of Devolutions Server. The root cause is a lack of server-side validation to ensure that the authenticated user requesting a deletion owns the message associated with the provided identifier. By supplying a direct object reference (ID) of a message belonging to another user, an attacker can successfully trigger its deletion. This vulnerability affects versions 2026.1.22 and earlier, as well as 2026.2.11 and earlier. Users should upgrade to versions 2026.1.23.0 or 2026.2.12.0 to remediate the issue.
Affected products
- Devolutions Server 2026.1.22 and earlier, 2026.2.11 and earlier
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory
- 2026-07-14: patched: Fixed in 2026.1.23.0 and 2026.2.12.0