Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- >= 2026.1.6.0, <= 2026.1.16.0
A vulnerability in the multi-factor authentication management feature of Devolutions Server has been identified, allowing an attacker with knowledge of a user's password to bypass multi-factor authentication. This issue arises after a user reconfigures their authentication factors. The vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0.
Exploitation of this vulnerability allows for unauthorized bypass of multi-factor authentication, potentially leading to unauthorized access to user accounts.
Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.