Devolutions Server Improper Access Control Vulnerability in Entry Activity Logs

Vulnerability

A vulnerability exists in Devolutions Server in the entry activity log feature, allowing an authenticated user with access to a specific entry, but lacking the necessary permissions, to retrieve that entry's activity logs through a manipulated API request. This issue impacts Devolutions Server versions 2026.1.6.0 to 2026.1.16.0, as well as all versions of Devolutions Server prior to 2025.3.20.0.

Impact

Exploitation of this vulnerability allows for unauthorized access to entry activity logs, potentially leading to privacy violations or misuse of activity data.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or version 2025.3.22.0 or higher.

Added: May 26, 2026, 3:43 PM
Updated: May 26, 2026, 3:43 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.