ZeroHour

CVE-2026-12105

CVSS 3.1
6.5 medium
EPSS
<1%p22
Published
()
Modified
Description

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.

Vendors
devolutions
Products
devolutions server
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.