SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-15641

HIGH · CVSS 7.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

An improper authorization vulnerability in the access request status endpoint of Devolutions Server allows authenticated low-privileged users to approve their own pending access requests without the necessary approver review. This flaw can lead to unauthorized access to sensitive resources, potentially compromising the integrity of the system. Organizations using affected versions of Devolutions Server should prioritize patching this vulnerability to mitigate the risk of unauthorized access.

CVE
CVE-2026-15641
Severity
HIGH
CVSS
7.1
EPSS
0.21%

Original NVD Description

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.

Related CVEs

Other vulnerabilities affecting the same vendor(s)