Feed/CVE-2026-15641
CVE-2026-15641HIGHCVSS 7.1

CVE-2026-15641

Published Jul 14, 2026·Updated Jul 30, 2026

NVD Description

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free