CVE-2026-3130: Devolutions Server

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

Affected products

  • Devolutions Devolutions Server: before 2025.3.16.0 (fixed in 2025.3.16.0)

Published 2026-03-03. Last modified 2026-06-17.