Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-15058

CVE-2026-15058: Devolutions Server Auth Bypass Flaw

CVE-2026-15058 is an authentication bypass flaw in Devolutions Server allowing authenticated users to delete other users' secure messages. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-15058 Overview

CVE-2026-15058 is an insecure direct object reference (IDOR) vulnerability in the secure messages deletion endpoint of Devolutions Server. The flaw affects versions 2026.2.11 and 2026.1.22. An authenticated user can delete another user's secure messages by supplying a direct object reference to the target message identifier. The vulnerability maps to CWE-639: Authorization Bypass Through User-Controlled Key.

Critical Impact

Any authenticated Devolutions Server user can delete secure messages belonging to other users, resulting in loss of integrity for stored communications.

Affected Products

  • Devolutions Server 2026.2.11
  • Devolutions Server 2026.1.22
  • Vendor: Devolutions

Discovery Timeline

  • 2026-07-14 - CVE-2026-15058 published to NVD
  • 2026-07-20 - Last updated in NVD database

Technical Details for CVE-2026-15058

Vulnerability Analysis

The vulnerability resides in the secure messages deletion endpoint of Devolutions Server. The endpoint accepts a message identifier from the request and performs deletion without verifying that the requesting user owns the referenced message. This missing ownership check enables horizontal privilege escalation across user accounts within the same Devolutions Server instance.

Secure messages in Devolutions Server are intended to convey sensitive information between authorized users. Unauthorized deletion undermines the integrity guarantees of that feature. Because the endpoint requires authentication, exploitation is limited to users who already possess valid credentials on the target server.

Root Cause

The root cause is missing server-side authorization enforcement on the deletion handler. The application trusts the client-supplied message identifier as sufficient authority for the delete operation. It does not cross-reference the message owner against the authenticated session principal before executing the delete.

Attack Vector

An attacker must hold valid credentials on the target Devolutions Server instance. The attacker enumerates or guesses message identifiers belonging to other users and issues a deletion request against the vulnerable endpoint. The server processes the request and removes the referenced message from the target user's mailbox. No user interaction is required from the victim.

No public proof-of-concept or exploit code is available for this vulnerability. See the Devolutions Security Advisory DEVO-2026-0024 for vendor guidance.

Detection Methods for CVE-2026-15058

Indicators of Compromise

  • Unexpected secure message deletion events in the Devolutions Server audit log attributed to users who did not create the affected messages.
  • User reports of missing secure messages that were not deleted by their intended recipient or sender.
  • Elevated request volume to the secure messages deletion endpoint from a single authenticated session.

Detection Strategies

  • Review Devolutions Server audit logs for delete operations where the acting user identifier does not match the message owner identifier.
  • Correlate deletion requests with session identity to flag cross-user deletion patterns.
  • Enable verbose logging on the secure messages module to capture request parameters and authenticated principal for each delete call.

Monitoring Recommendations

  • Forward Devolutions Server audit logs to a centralized SIEM for long-term retention and correlation.
  • Alert on bursts of secure message deletion events initiated by non-administrator accounts.
  • Baseline normal deletion activity per user and alert on statistical outliers.

How to Mitigate CVE-2026-15058

Immediate Actions Required

  • Upgrade Devolutions Server to a fixed release as specified in the vendor advisory DEVO-2026-0024.
  • Audit historical secure message deletion events to identify any unauthorized removals prior to patching.
  • Restrict Devolutions Server access to trusted user populations while patching is scheduled.

Patch Information

Devolutions has published a security advisory documenting affected versions and fixed releases. Refer to the Devolutions Security Advisory DEVO-2026-0024 for the specific fixed build numbers and upgrade procedures. Versions 2026.2.11 and 2026.1.22 are confirmed vulnerable.

Workarounds

  • No vendor-supplied workaround is documented; upgrading to the patched release is the recommended remediation.
  • Reduce the authenticated user population that can access the secure messages feature until the patch is applied.
  • Increase audit log review frequency to detect unauthorized deletions during the exposure window.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.