CVE-2026-1007

CVE-2026-1007

Vendor Devolutions
Product Server
Weakness CWE-863 · Incorrect authorization
Published January 19, 2026
Last update January 20, 2026

CVSS base score

What the vulnerability does

01Description

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.

Key dates

02Disclosure timeline

January 19, 2026 CVE published
January 20, 2026 Record updated