CVE-2026-5171
Estado: AnalizadaMedia (4.3)—
Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request.
This issue affects :
Detalles técnicos trazas, registros y código del informe original
* Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 17
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-284
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-5171",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-5171",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-22T16:49:58.273868Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@devolutions.net",
"affectedData": [
{
"vendor": "Devolutions",
"product": "Server",
"versions": [
{
"status": "affected",
"version": "2026.1.6.0",
"versionType": "custom",
"lessThanOrEqual": "2026.1.16.0"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2025.3.20.0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-22T16:16:21.103",
"references": [
{
"url": "https://devolutions.net/security/advisories/DEVO-2026-0013/",
"tags": [
"Vendor Advisory"
],
"source": "security@devolutions.net"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@devolutions.net",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request.\n\nThis issue affects :\n\n * Devolutions Server 2026.1.6.0 through 2026.1.16.0\n * Devolutions Server 2025.3.20.0 and earlier"
},
{
"lang": "es",
"value": "Control de acceso inadecuado en la función de registro de actividad de entrada en Devolutions Server permite a un usuario autenticado con acceso a una entrada pero sin el permiso requerido recuperar los registros de actividad de esa entrada a través de una solicitud de API manipulada.\n\nEste problema afecta a :\n\n * Devolutions Server 2026.1.6.0 hasta 2026.1.16.0\n * Devolutions Server 2025.3.20.0 y versiones anteriores"
}
],
"lastModified": "2026-07-23T16:10:00.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E689234-ABCB-49B5-AD17-00C2E2FC3B11",
"versionEndExcluding": "2025.3.22.0"
},
{
"criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02811CA7-5B80-47D7-B826-18B3CB1213E9",
"versionEndExcluding": "2026.1.19.0",
"versionStartIncluding": "2026.1.6.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@devolutions.net"
}