Devolutions Server Improper Access Control Vulnerability in Notification Management Endpoints

Vulnerability

A vulnerability exists in Devolutions Server in the notification management endpoints, where improper access control allows an unauthenticated attacker to modify or delete user notification records. This issue arises from inadequate session validation. The vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.15.0, as well as versions 2025.3.19.0 and earlier.

Impact

Exploitation of this vulnerability allows for unauthorized modification or deletion of user notification records.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.16.0 or higher, or to version 2025.3.20.0 or higher.

Added: May 12, 2026, 9:13 PM
Updated: May 12, 2026, 9:13 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
7.4
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.