Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- >= 2026.1.6, <= 2026.1.11
- <= 2025.3.17
A vulnerability exists in the multi-factor authentication (MFA) management API of Devolutions Server, specifically in versions 2026.1.6 through 2026.1.11. This vulnerability allows an authenticated attacker to delete their own MFA factors, reverting their account security to password-only authentication, by sending crafted HTTP requests. The issue arises from improper access control, which enables users to bypass restrictions and manipulate their MFA settings.
Exploitation of this vulnerability allows for the removal of multi-factor authentication, leaving accounts protected only by passwords.
Users are advised to upgrade to Devolutions Server version 2026.1.12 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.