Improper Access Control in Devolutions Server Affects User Notifications
CVE-2026-5146
4.3MEDIUM
What is CVE-2026-5146?
In Devolutions Server, a security flaw in the notification management endpoints permits an unauthenticated attacker to alter or delete user notification records due to a lack of proper session validation. This vulnerability could lead to unauthorized changes to critical user data, impacting trust and the integrity of user communications.
Affected Version(s)
Server 2026.1.6.0 <= 2026.1.15.0
Server 0 <= 2025.3.19.0
