Home

Description

Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier

PUBLISHED Reserved 2026-06-03 | Published 2026-06-08 | Updated 2026-06-08 | Assigner DEVOLUTIONS

Problem types

CWE-862 Missing authorization

Product status

Default status
unaffected

2026.2.4.0 (custom)
affected

Any version
affected

References

devolutions.net/security/advisories/DEVO-2026-0015/

cve.org (CVE-2026-10787)

nvd.nist.gov (CVE-2026-10787)

Download JSON