PT-2026-3442 · Devolutions · Devolutions Server

Published

2026-01-19

·

Updated

2026-02-10

·

CVE-2026-1007

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2025.3.1 through 2025.3.12
Description An incorrect authorization issue exists in the virtual gateway component of Devolutions Server. This allows attackers to bypass deny IP rules.
Recommendations Update Devolutions Server to a version later than 2025.3.12.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1007

Affected Products

Devolutions Server