PatchSiren cyber security CVE debrief
CVE-2026-15058 Devolutions CVE debrief
CVE-2026-15058 is an improper authorization vulnerability in Devolutions Server, specifically affecting versions 2026.2.11 and 2026.1.22. An authenticated user can delete another user's messages via direct object reference to the message identifier. This issue has a CVSS score of 3.1 and is classified as LOW severity. The vulnerability allows an attacker to bypass authorization checks, potentially leading to unauthorized message deletion. Users of Devolutions Server should apply patches promptly to prevent exploitation.
- Vendor
- Devolutions
- Product
- Devolutions Server
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-30
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-30
Who should care
Users of Devolutions Server 2026.2.11 and 2026.1.22 should apply patches to prevent unauthorized message deletion. Additionally, security teams and administrators responsible for Devolutions Server deployments should review the vulnerability details and assess their exposure. Platform operators and vulnerability management teams should prioritize patching and monitor for potential security incidents related to this vulnerability.
Technical summary
The secure messages deletion endpoint in Devolutions Server 2026.2.11 and 2026.1.22 does not properly authorize users, allowing an authenticated user to delete messages belonging to another user via a direct object reference to the message identifier. This issue has a CVSS score of 3.1 and is classified as LOW severity. The vulnerability is caused by inadequate authorization checks in the secure messages deletion endpoint.
Defensive priority
Apply patches promptly to prevent exploitation. Restrict access to the secure messages deletion endpoint and monitor for unauthorized message deletion attempts.
Recommended defensive actions
- Apply patches for Devolutions Server 2026.2.11 and 2026.1.22
- Restrict access to secure messages deletion endpoint
- Monitor for unauthorized message deletion attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-14T19:16:50.817Z and was last modified on 2026-07-20T02:15:47.187Z. The NVD entry is currently Analyzed. Evidence from the CVE record and NVD entry indicates that Devolutions Server 2026.2.11 and 2026.1.22 are affected. However, details on the number of affected deployments and specific configurations are not provided. Defenders should verify the scope of affected systems and review system logs for potential unauthorized message deletion attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15058 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15058
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15058 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15058
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://devolutions.net/security/advisories/DEVO-2026-0024/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.