CVE-2026-5171
Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but wit
CVSS
4.3
Medium
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Published: May 22, 2026 · Last modified: Jul 23, 2026 · CWE-284
0.2%EPSS · 30 days0.2%
2026-07-292026-08-26
Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-614197.8 HIG0.7%
——0Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.2dCVE-2026-782457.3 HIG39.0%
——12A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.3dCVE-2026-782027.3 HIG20.8%
——6A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.3dCVE-2026-76609—14.8%
——4Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.3dCVE-2026-76608—21.6%
——6Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.3dCVE-2026-76607—14.8%
——4Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.3d