Devolutions Server Two-Factor Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing the bypass of two-factor authentication (2FA) has been identified in Devolutions Server versions through 2026.1.11. This issue arises from improper authentication in the 2FA feature, which enables a remote attacker with valid credentials to circumvent multifactor authentication and gain unauthorized access to a victim's account by reusing a partially authenticated session token.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts, including those of administrators, by bypassing multifactor authentication.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.12.0 or higher, or version 2025.3.18 or higher.

Added: Apr 1, 2026, 4:35 PM
Updated: Apr 1, 2026, 4:35 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.2
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.