SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-15058

LOW · CVSS 3.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

An improper authorization vulnerability in the secure messages deletion endpoint of Devolutions Server allows authenticated users to delete messages belonging to other users by manipulating the message identifier. This could lead to unauthorized data loss and compromise user privacy. Organizations using affected versions of Devolutions Server should prioritize remediation to protect against potential misuse of this flaw.

CVE
CVE-2026-15058
Severity
LOW
CVSS
3.1
EPSS
0.16%

Original NVD Description

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.

Related CVEs

Other vulnerabilities affecting the same vendor(s)