Executive brief
Devolutions Server, a self-hosted platform for managing credentials and remote connections, contains a security flaw in its notification system. An unauthorized person could exploit this to modify or delete notification records belonging to other users. This could lead to missed security alerts or the disruption of administrative communications within the organization.
Technical details
An improper access control vulnerability exists in the notification management endpoints of Devolutions Server. The flaw is caused by missing session validation, which allows an unauthenticated attacker to interact with these endpoints over the network. By exploiting this, an attacker can modify or delete arbitrary user notification records. The vulnerability affects versions 2026.1.6.0 through 2026.1.15.0 and versions 2025.3.19.0 and earlier. While the advisory mentions unauthenticated access in the description, the provided CVSS 3.1 vector (PR:L) suggests low privileges may be required in some contexts; however, the primary root cause is the lack of proper authorization checks on the management endpoints.
Affected products
- Devolutions Devolutions Server 2026.1.6.0 through 2026.1.15.0, 2025.3.19.0 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory