VYPR
Unrated severityNVD Advisory· Published Jan 19, 2026· Updated Jan 20, 2026

CVE-2026-1007

CVE-2026-1007

Description

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.

Affected products

2
  • Bitwarden/Serverllm-fuzzy
    Range: >=2025.3.1 <=2025.3.12
  • Devolutions/Serverv5
    Range: 2025.3.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.