Description
Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
Published: 2026-07-14
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user can delete another user's messages by using the secure messages deletion endpoint. This improper authorization flaw allows arbitrary deletion of messages via direct object reference to the message identifier. The flaw does not allow code execution or network compromise; it primarily affects confidentiality and availability of user data.

Affected Systems

Devolutions Server versions 2026.2.11 and 2026.1.22 are affected. The Devolutions:Server product is impacted; no other versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 3.1 indicates a low severity risk. The EPSS score of less than 1 percent signals a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires valid credentials for an authenticated user and the ability to provide a message identifier. Attackers would acquire the advantage of deleting messages belonging to other users, leading to loss of information and potential violation of data handling policies.

Generated by OpenCVE AI on July 31, 2026 at 05:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑provided patch from the Devolutions security advisory to fix the authorization issue.
  • Restrict delete permissions so that only administrators can delete messages, ensuring non‑privileged users do not have access to the deletion endpoint.
  • Review and enforce role‑based access controls to prevent unauthorized message deletion.
  • If a patch cannot be applied immediately, monitor for and apply any interim updates from Devolutions as they become available.

Generated by OpenCVE AI on July 31, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enables Deletion of Other Users' Messages

Wed, 29 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Devolutions Server Secure Messages Deletion Endpoint

Sat, 25 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Devolutions Server Secure Messages Deletion Endpoint

Fri, 17 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Message Deletion via Direct Object Reference

Thu, 16 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Message Deletion via Direct Object Reference

Wed, 15 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
Weaknesses CWE-639
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-15T14:46:13.929Z

Reserved: 2026-07-08T13:55:05.553Z

Link: CVE-2026-15058

cve-icon Vulnrichment

Updated: 2026-07-15T14:44:25.453Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key