Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation.
This issue affects the following versions :
*
Devolutions Server 2026.1.6.0 through 2026.1.15.0
*
Devolutions Server 2025.3.19.0 and earlier
This issue affects the following versions :
*
Devolutions Server 2026.1.6.0 through 2026.1.15.0
*
Devolutions Server 2025.3.19.0 and earlier
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0012 |
|
History
Tue, 12 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Modification of User Notification Records in Devolutions Server |
Tue, 12 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.15.0 * Devolutions Server 2025.3.19.0 and earlier | |
| Weaknesses | CWE-862 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-05-12T17:28:21.264Z
Reserved: 2026-03-30T13:23:11.124Z
Link: CVE-2026-5146
No data.
Status : Received
Published: 2026-05-12T18:17:32.177
Modified: 2026-05-12T18:17:32.177
Link: CVE-2026-5146
No data.
OpenCVE Enrichment
Updated: 2026-05-12T20:00:13Z
Weaknesses