PT-2026-40335 · Devolutions · Devolutions Server

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-5146

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Server versions 2026.1.6.0 through 2026.1.15.0 Devolutions Server versions 2025.3.19.0 and earlier
Description Improper access control in the notification management endpoints allows an unauthenticated attacker to modify or delete arbitrary user notification records due to missing session validation.
Recommendations Update Devolutions Server versions 2026.1.6.0 through 2026.1.15.0 to a patched version. Update Devolutions Server versions 2025.3.19.0 and earlier to a patched version.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-5146

Affected Products

Devolutions Server