Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2026.1.11
- <= 2025.3.17
A vulnerability exists in Devolutions Server in versions through 2026.1.11 and 2025.3.17, where improper authentication in the external OAuth authentication flow allows an authenticated user to impersonate other users, including administrators. This is achieved by reusing a session code from an external authentication flow.
Exploitation of this vulnerability allows for user impersonation, potentially leading to unauthorized access and actions as the impersonated user, including administrative privileges.
Users are advised to upgrade to Devolutions Server version 2026.1.12.0 or higher, or 2025.3.18 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.