Devolutions Server Entry Status Management Authorization Bypass Vulnerability

Vulnerability

An authorization bypass vulnerability has been identified in the entry status management feature of Devolutions Server. This issue allows non-administrator authenticated users to circumvent the Pending Approval process enforced by administrators. Affected users can access an entry's data by sending a crafted status change request. The vulnerability is present in Devolutions Server versions 2026.1.6.0 through 2026.1.16.0, as well as in versions 2025.3.20.0 and earlier.

Impact

Exploitation of this vulnerability allows unauthorized access to entry data by bypassing the administrator-required Pending Approval process.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or version 2025.3.22.0 or higher.

Added: May 26, 2026, 3:31 PM
Updated: May 26, 2026, 3:31 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.3
exploitability
4.8
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.