PatchSiren cyber security CVE debrief
CVE-2026-15058 Devolutions CVE debrief
CVE-2026-15058 is an improper authorization vulnerability in Devolutions Server, specifically affecting versions 2026.2.11 and 2026.1.22. An authenticated user can delete another user's messages via direct object reference to the message identifier. This issue has a CVSS score of 3.1 and is classified as LOW severity. The vulnerability allows an attacker to bypass authorization checks, potentially leading to unauthorized message deletion. Users of Devolutions Server should apply patches promptly to prevent exploitation.
- Vendor
- Devolutions
- Product
- Devolutions Server
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-20
Who should care
Users of Devolutions Server 2026.2.11 and 2026.1.22 should apply patches to prevent unauthorized message deletion. Additionally, security teams and administrators responsible for Devolutions Server deployments should review the vulnerability details and assess their exposure. Platform operators and vulnerability management teams should prioritize patching and monitor for potential security incidents related to this vulnerability.
Technical summary
The secure messages deletion endpoint in Devolutions Server 2026.2.11 and 2026.1.22 does not properly authorize users, allowing an authenticated user to delete messages belonging to another user via a direct object reference to the message identifier. This issue has a CVSS score of 3.1 and is classified as LOW severity. The vulnerability is caused by inadequate authorization checks in the secure messages deletion endpoint.
Defensive priority
Apply patches promptly to prevent exploitation. Restrict access to the secure messages deletion endpoint and monitor for unauthorized message deletion attempts.
Recommended defensive actions
- Apply patches for Devolutions Server 2026.2.11 and 2026.1.22
- Restrict access to secure messages deletion endpoint
- Monitor for unauthorized message deletion attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-14T19:16:50.817Z and was last modified on 2026-07-20T02:15:47.187Z. The NVD entry is currently Analyzed. Evidence from the CVE record and NVD entry indicates that Devolutions Server 2026.2.11 and 2026.1.22 are affected. However, details on the number of affected deployments and specific configurations are not provided. Defenders should verify the scope of affected systems and review system logs for potential unauthorized message deletion attempts.
Official resources
-
CVE-2026-15058 CVE record
CVE.org
-
CVE-2026-15058 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T19:16:50.817Z and has not been modified since then. The NVD entry is currently Analyzed.