Devolutions Server Multi-Factor Authentication Bypass Vulnerability

Vulnerability

A vulnerability in the multi-factor authentication management feature of Devolutions Server has been identified, allowing an attacker with knowledge of a user's password to bypass multi-factor authentication. This issue arises after a user reconfigures their authentication factors. The vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0.

Impact

Exploitation of this vulnerability allows for unauthorized bypass of multi-factor authentication, potentially leading to unauthorized access to user accounts.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher.

Added: May 26, 2026, 3:40 PM
Updated: May 26, 2026, 3:40 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.6
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.