Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-3130

Опубликовано: 03 мар. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Версия до 2025.3.16.0 (исключая)

EPSS

Процентиль: 42%
0.00522
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-841

Связанные уязвимости

CVSS3: 9.8
github
7 месяцев назад

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

EPSS

Процентиль: 42%
0.00522
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-841