
CVE-2026-3131 Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-only permission to ac… https://www.cve.org/CVERecord?id=CVE-2026-3131
Post summary
The text announces CVE‑2026‑3131, describing an improper access control flaw in Devolutions Server’s REST API that allows view‑only users to access restricted data.

