CVE-2026-15641: High severity Devolutions Devolutions Server vulnerability
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15641?
CVE-2026-15641 has a severity score of 7.1, which is classified as high.
How do I fix CVE-2026-15641?
To fix CVE-2026-15641, you should update Devolutions Server to version 2026.2.12 or later.
What vulnerability does CVE-2026-15641 address?
CVE-2026-15641 addresses improper authorization in the access request status endpoint.
Who is affected by CVE-2026-15641?
Authenticated low-privileged users in Devolutions Server versions 2026.2.11 and 2026.1.22 are affected by CVE-2026-15641.
What could happen if CVE-2026-15641 is exploited?
If exploited, CVE-2026-15641 allows low-privileged users to approve their own pending access requests, bypassing required approver review.