CVE-2026-5146

Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.15.0 * Devolutions Server 2025.3.19.0 and earlier
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

26 May 2026, 12:51

Type Values Removed Values Added
First Time Devolutions devolutions Server
Devolutions
References () https://devolutions.net/security/advisories/DEVO-2026-0012 - () https://devolutions.net/security/advisories/DEVO-2026-0012 - Vendor Advisory
CPE cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

13 May 2026, 16:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

12 May 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 18:17

Updated : 2026-05-26 12:51


NVD link : CVE-2026-5146

Mitre link : CVE-2026-5146

CVE.ORG link : CVE-2026-5146


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-862

Missing Authorization