Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.
References
| Link | Resource |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0014/ | Vendor Advisory |
Configurations
History
02 Jun 2026, 20:53
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Devolutions devolutions Server
Devolutions |
|
| CPE | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
| References | () https://devolutions.net/security/advisories/DEVO-2026-0014/ - Vendor Advisory |
02 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
02 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-02 16:16
Updated : 2026-06-02 20:53
NVD link : CVE-2026-9590
Mitre link : CVE-2026-9590
CVE.ORG link : CVE-2026-9590
JSON object : View
Products Affected
devolutions
- devolutions_server
CWE
CWE-284
Improper Access Control
