Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- >= 2026.1.6, <= 2026.1.11
A vulnerability in the multi-factor authentication (MFA) feature of Devolutions Server allows users with user management privileges to access other users' one-time password (OTP) keys through an authenticated API request. This issue affects Devolutions Server versions 2026.1.6 prior to 2026.1.11.
Exploitation of this vulnerability could lead to unauthorized access to users' MFA OTP keys, potentially allowing for impersonation or unauthorized actions on behalf of those users.
Users are advised to upgrade to Devolutions Server version 2026.1.12 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.