---
id: CVE-2026-105488
title: >-
  Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and
  earlier allows an authenticated user with only the global vault view
  permission to modify and delete global contact and folder entries.
summary: >-
  Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and
  earlier allows an authenticated user with only the global vault view
  permission to modify and delete global contact and folder entries.
severity: none
cwe:
  - CWE-862
vendor: Devolutions
product: Server
affected:
  - Server < 2026.3.8
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T19:58:37.060'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105488'
references:
  - url: 'https://devolutions.net/security/advisories/DEVO-2026-0035/'
    label: security@devolutions.net
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T19:13:33.940Z'
---

## Overview

Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and earlier allows an authenticated user with only the global vault view permission to modify and delete global contact and folder entries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
