CVE-2026-9590: Medium severity Devolutions Devolutions Server vulnerability
Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Restrict or disable assignment of 'entry edit' privileges to only trusted administrator accounts until a vendor patch/fixed release is applied.
Devolutions Server entry_edit_privileges = restricted to trusted administrators - Compensating control
Enable monitoring/logging and alerts for modifications to asset information and restrict access to the Devolutions Server management interfaces to trusted IP ranges or networks while awaiting a vendor fix.
- Operational
Audit all user accounts and groups for 'entry edit' privileges; remove or reduce privileges for accounts that do not require them for their role and document changes.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9590?
The severity of CVE-2026-9590 is medium with a CVSS score of 5.3.
How do I fix CVE-2026-9590?
To fix CVE-2026-9590, upgrade to Devolutions Server version 2026.1.20 or later.
What types of systems are affected by CVE-2026-9590?
CVE-2026-9590 affects Devolutions Server versions 2026.1.19 and earlier.
What kind of vulnerability is CVE-2026-9590?
CVE-2026-9590 is an improper access control vulnerability in the permission validation component.
What can an attacker do with CVE-2026-9590?
An authenticated user with entry edit privileges can modify asset information without the required permission due to CVE-2026-9590.