CVE-2026-9590
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.
Affected (1)
Products: Devolutions: Devolutions Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2026.1.20.0 |
References (1)
Source: security@devolutions.net
Vendor Advisory
Timeline
No history available yet.