MEDIUM
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation
Published May 12, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.27%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.