Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows
an authenticated user to access attachments via folder duplication with
inherited permissions.
an authenticated user to access attachments via folder duplication with
inherited permissions.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0017/ |
|
History
Tue, 16 Jun 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions devolutions Server |
|
| Vendors & Products |
Devolutions
Devolutions devolutions Server |
Tue, 16 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions. | |
| Weaknesses | CWE-862 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-06-16T18:28:04.584Z
Reserved: 2026-06-12T14:29:02.015Z
Link: CVE-2026-12105
No data.
Status : Awaiting Analysis
Published: 2026-06-16T20:16:27.483
Modified: 2026-06-16T20:41:35.520
Link: CVE-2026-12105
No data.
OpenCVE Enrichment
Updated: 2026-06-16T21:00:12Z
Weaknesses