Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2026.1.11
- <= 2025.3.17
A vulnerability exists in the OAuth login process of Devolutions Server versions through 2026.1.11. This flaw allows remote attackers with valid credentials to bypass multi-factor authentication by sending a crafted login request. The issue arises from improper authentication handling, enabling attackers to exploit the login flow and gain unauthorized access.
Exploitation of this vulnerability allows for user impersonation, as authenticated users can authenticate as other users, including administrators, by reusing a session code from an external authentication flow.
Users are advised to upgrade to Devolutions Server version 2026.1.12.0 or higher, or 2025.3.18 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.