7.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N
Description
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.
Basic Information
ID
CVE-2026-1007
Source
DEVOLUTIONS
Published
Jan 19, 2026 at 14:32
Modified
Jan 20, 2026 at 15:02
Affected Product
Vendor
Devolutions
Product
Server
Version
2025.3.1
Affected Versions
Devolutions Server 2025.3.1