HomeDefault status
unaffected
Any version before 2026.2.5
affected
Any version before 2026.1.21
affected
Description
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.
Problem types
Product status
Any version before 2026.2.5
Any version before 2026.1.21
References
devolutions.net/security/advisories/DEVO-2026-0017/