Junglewise Threat Intelligence

CVE-2026-5171: Devolutions Server Improper Access Control in Entry Activity Logs

CVE-2026-5171 · Severity: medium · CVSS 4.3 · Published 2026-05-22

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and passwords, contains a security flaw in its activity logging feature. An authorized user who has access to a specific entry can bypass permission checks to view that entry's full activity history, even if they are not supposed to have auditing rights. This could lead to the unauthorized disclosure of sensitive operational logs and user activity data.

Technical details

An improper access control vulnerability (CWE-284) exists in the entry activity log feature of Devolutions Server. The application fails to properly validate if an authenticated user possesses the specific auditing permissions required to view activity logs for a given entry. By sending a specially crafted API request, a user who has basic access to an entry can bypass these checks to retrieve its historical logs. This issue affects versions 2026.1.6.0 through 2026.1.16.0 and versions 2025.3.20.0 and earlier. Users are advised to upgrade to Devolutions Server 2026.1.19.0 or 2025.3.22.0 to remediate the vulnerability.

Affected products

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0, 2025.3.20.0 and earlier

Timeline

  • 2026-05-21: disclosed: Initial publication of vendor advisory DEVO-2026-0013
  • 2026-05-22: advisory: NVD publication date

References