Home

Description

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

PUBLISHED Reserved 2026-02-24 | Published 2026-03-03 | Updated 2026-03-03 | Assigner DEVOLUTIONS

Problem types

CWE-841: Improper Enforcement of Behavioral Workflow

Product status

Default status
unaffected

Any version before 2025.3.16
affected

References

devolutions.net/security/advisories/DEVO-2026-0005

cve.org (CVE-2026-3130)

nvd.nist.gov (CVE-2026-3130)

Download JSON