CVE-2026-1768: Medium severity Devolutions Server vulnerability
Published Feb 24, 2026
·Updated
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.
Affected Software
2 affected components
Devolutions Server<2025.3.15
Devolutions Devolutions Server<2025.3.15.0
Event History
Feb 24, 2026
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
DescriptionWeakness
Data Sourced
via NVD·08:27 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-1768?
CVE-2026-1768 is considered a critical vulnerability due to its ability to allow authenticated users to bypass permissions.
2
How do I fix CVE-2026-1768?
To mitigate CVE-2026-1768, upgrade your Devolutions Server to version 2025.3.15 or later.
3
Who is affected by CVE-2026-1768?
CVE-2026-1768 affects all versions of Devolutions Server prior to 2025.3.15.
4
What type of vulnerability is CVE-2026-1768?
CVE-2026-1768 is a permission cache poisoning vulnerability related to access control.
5
What should I do if I cannot upgrade to fix CVE-2026-1768?
If immediate upgrade is not possible, consider reviewing and restricting user permissions as a temporary workaround against CVE-2026-1768.