CVE-2026-3638: Devolutions Server
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated user to restore deleted users and roles via crafted API requests.
Affected products
- Devolutions Devolutions Server: before 2025.3.12.0 (fixed in 2025.3.12.0)
Published 2026-03-09. Last modified 2026-06-17.