Improper Enforcement of Behavioral Controls in Devolutions Server by Devolutions
CVE-2026-3130

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
3 March 2026

What is CVE-2026-3130?

An improper enforcement of behavioral controls in Devolutions Server 2025.3.15 and earlier allows authenticated users with delete permissions to perform bulk deletions. This capability could enable attackers to remove a PAM account currently being used by selecting it alongside other non-checked-out accounts, posing a security risk to system integrity and user data management.

Affected Version(s)

Server 0 < 2025.3.16

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.