Authorization Flaw in Devolutions Server Allows Unauthorized Modification of Vault Attachments
CVE-2026-100287

Currently unrated

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100287?

A security vulnerability in Devolutions Server versions 2026.3.5.0 and earlier arises from a lack of proper authorization checks in the attachment history API. This oversight allows authenticated users with low privileges to exploit the API by sending specially crafted requests, enabling them to delete or restore vault attachments without proper permissions. Such misuse can lead to unauthorized alterations in sensitive data management, posing significant risks to data integrity and availability.

Affected Version(s)

Server 0 < 2026.3.7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.