Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- 2026.2.4.0
- 2026.1.20.0
A vulnerability exists in the Devolutions Server deleted user groups API, where missing authorization allows an authenticated low-privileged user to enumerate metadata of deleted user groups through a crafted API request. This issue affects Devolutions Server versions 2026.2.4.0, 2026.1.20.0 and earlier.
Exploitation of this vulnerability allows for unauthorized enumeration of metadata related to deleted user groups.
Users are advised to upgrade to Devolutions Server version 2026.2.5.0 or higher, or version 2026.1.21.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.