CVE-2026-3638 PUBLISHED

Assigner: DEVOLUTIONS
Reserved: 06.03.2026 Published: 09.03.2026 Updated: 09.03.2026

Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated user to restore deleted users and roles via crafted API requests.

Product Status

Vendor Devolutions
Product Server
Versions Default: unaffected
  • affected from 0 to 2025.3.11.0 (incl.)

References

Problem Types

  • CWE-862: Missing Authorization CWE