CVE-2026-100287
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Sep 29, 2026
Vendor
unknown
Description
Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request.