Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- <= 2026.1.11
- <= 2025.3.17
A vulnerability allowing the bypass of two-factor authentication (2FA) has been identified in Devolutions Server versions through 2026.1.11. This issue arises from improper authentication in the 2FA feature, which enables a remote attacker with valid credentials to circumvent multifactor authentication and gain unauthorized access to a victim's account by reusing a partially authenticated session token.
Exploitation of this vulnerability allows for unauthorized access to user accounts, including those of administrators, by bypassing multifactor authentication.
Users are advised to upgrade to Devolutions Server version 2026.1.12.0 or higher, or version 2025.3.18 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.