« Volver al listado

CVE-2026-5171

Estado: AnalizadaMedia (4.3)—

Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request.

This issue affects :

Detalles técnicos trazas, registros y código del informe original
  *  Devolutions Server 2026.1.6.0 through 2026.1.16.0
  *  Devolutions Server 2025.3.20.0 and earlier

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-5171",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-5171",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-22T16:49:58.273868Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@devolutions.net",
      "affectedData": [
        {
          "vendor": "Devolutions",
          "product": "Server",
          "versions": [
            {
              "status": "affected",
              "version": "2026.1.6.0",
              "versionType": "custom",
              "lessThanOrEqual": "2026.1.16.0"
            },
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2025.3.20.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-22T16:16:21.103",
  "references": [
    {
      "url": "https://devolutions.net/security/advisories/DEVO-2026-0013/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@devolutions.net"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@devolutions.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request.\n\nThis issue affects :\n\n  *  Devolutions Server 2026.1.6.0 through 2026.1.16.0\n  *  Devolutions Server 2025.3.20.0 and earlier"
    },
    {
      "lang": "es",
      "value": "Control de acceso inadecuado en la función de registro de actividad de entrada en Devolutions Server permite a un usuario autenticado con acceso a una entrada pero sin el permiso requerido recuperar los registros de actividad de esa entrada a través de una solicitud de API manipulada.\n\nEste problema afecta a :\n\n  *  Devolutions Server 2026.1.6.0 hasta 2026.1.16.0\n  *  Devolutions Server 2025.3.20.0 y versiones anteriores"
    }
  ],
  "lastModified": "2026-07-23T16:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E689234-ABCB-49B5-AD17-00C2E2FC3B11",
              "versionEndExcluding": "2025.3.22.0"
            },
            {
              "criteria": "cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02811CA7-5B80-47D7-B826-18B3CB1213E9",
              "versionEndExcluding": "2026.1.19.0",
              "versionStartIncluding": "2026.1.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@devolutions.net"
}