Vulnerability Details CVE-2026-1007
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.3%
CVSS Severity
CVSS v3 Score 7.6
Products affected by CVE-2026-1007
-
cpe:2.3:a:devolutions:devolutions_server:2025.3.10.0
-
cpe:2.3:a:devolutions:devolutions_server:2025.3.2.0
-
cpe:2.3:a:devolutions:devolutions_server:2025.3.3.0
-
cpe:2.3:a:devolutions:devolutions_server:2025.3.4.0
-
cpe:2.3:a:devolutions:devolutions_server:2025.3.5.0
-
cpe:2.3:a:devolutions:devolutions_server:2025.3.6.0
-
cpe:2.3:a:devolutions:devolutions_server:2025.3.7.0
-
cpe:2.3:a:devolutions:devolutions_server:2025.3.8.0