Devolutions Server Emergency Authentication Weak Credentials Authentication Bypass Vulnerability

Vulnerability

A vulnerability exists in the emergency authentication component of Devolutions Server, allowing an unauthenticated attacker to bypass authentication. This is achieved by brute-forcing the short emergency codes generated by the server, which can be done within a feasible timeframe. The issue affects Devolutions Server versions 2025.2.2.0 through 2025.2.3.0, as well as version 2025.1.11.0 and earlier.

Impact

Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized access to the application or system.

Remediation

Users are advised to upgrade to Devolutions Server version 2025.2.4.0 or higher.

Added: Jul 22, 2025, 5:18 PM
Updated: Jul 22, 2025, 7:28 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.