Impact
An authenticated user can delete another user's messages by using the secure messages deletion endpoint. This improper authorization flaw allows arbitrary deletion of messages via direct object reference to the message identifier. The flaw does not allow code execution or network compromise; it primarily affects confidentiality and availability of user data.
Affected Systems
Devolutions Server versions 2026.2.11 and 2026.1.22 are affected. The Devolutions:Server product is impacted; no other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity risk. The EPSS score of less than 1 percent signals a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires valid credentials for an authenticated user and the ability to provide a message identifier. Attackers would acquire the advantage of deleting messages belonging to other users, leading to loss of information and potential violation of data handling policies.
OpenCVE Enrichment