CVE-2026-12105

EUVD-2026-37203
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows
 an authenticated user to access attachments via folder duplication with
 inherited permissions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
devolutionsdevolutions_server
𝑥
< 2026.1.22.0
devolutionsdevolutions_server
2026.2.4.0 ≤
𝑥
< 2026.2.7.0
𝑥
= Vulnerable software versions