Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- >= 2026.1.6.0, <= 2026.1.16.0
- <= 2025.3.20.0
A vulnerability exists in Devolutions Server in the entry activity log feature, allowing an authenticated user with access to a specific entry, but lacking the necessary permissions, to retrieve that entry's activity logs through a manipulated API request. This issue impacts Devolutions Server versions 2026.1.6.0 to 2026.1.16.0, as well as all versions of Devolutions Server prior to 2025.3.20.0.
Exploitation of this vulnerability allows for unauthorized access to entry activity logs, potentially leading to privacy violations or misuse of activity data.
Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or version 2025.3.22.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.