CVE-2026-3130: Devolutions Server
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.
Affected products
- Devolutions Devolutions Server: before 2025.3.16.0 (fixed in 2025.3.16.0)
Published 2026-03-03. Last modified 2026-06-17.