Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.
Remediation and Workarounds
Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later
5.4 Medium - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Improper access control on account discovery scan configurations
Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.
Remediation and Workarounds
Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later
2.1 Low - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Improper access control in the Synchronizer feature
Improper access control in the Synchronizer feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user to use sealed credentials without triggering unseal prompts or administrator notifications via synchronizer entries.
Remediation and Workarounds
Upgrade to Devolutions Server 2026.2.4 or later, 2026.1.20 or later
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
