CVE-2026-5146 — Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session va — CVE Database · The Intelligence Room