CVE-2026-1007: High severity Devolutions Server vulnerability
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1007?
CVE-2026-1007 has a high severity rating, as it allows unauthorized access due to incorrect authorization in the virtual gateway component.
How does CVE-2026-1007 affect Devolutions Server?
CVE-2026-1007 affects Devolutions Server versions from 2025.3.1 to 2025.3.12, enabling attackers to bypass IP deny rules.
How do I fix CVE-2026-1007?
To fix CVE-2026-1007, upgrade your Devolutions Server to a version that is higher than 2025.3.12.
What are the potential impacts of CVE-2026-1007?
The potential impacts of CVE-2026-1007 include unauthorized access to sensitive server data and systems.
Is there a workaround for CVE-2026-1007?
Currently, there is no official workaround for CVE-2026-1007, so the recommended action is to update to a patched version.