Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.3

Devolutions Server: Authenticated Users Can Bypass Entry Permissions

CVE-2026-1768
Summary

Authenticated users can access entries they shouldn't be able to, potentially exposing sensitive data. This issue affects Devolutions Server versions before 2025.3.15. To protect your data, update to version 2025.3.15 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
devolutions devolutions_server <= 2025.3.15.0 –
Original title
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.
Original description
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.
nvd CVSS3.1 4.3
Vulnerability type
CWE-863 Incorrect Authorization
Published: 24 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026