PT-2026-24100 · Devolutions · Devolutions Server

Published

2026-03-09

·

Updated

2026-03-09

·

CVE-2026-3638

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.3.11.0 and earlier
Description An issue exists in the user and role restore API endpoints that allows a low-privileged authenticated user to restore deleted users and roles by sending specially crafted API requests. The affected API endpoints are vulnerable due to improper access control.
Recommendations Update Devolutions Server to a version later than 2025.3.11.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3638

Affected Products

Devolutions Server