Devolutions Server Open Redirect Vulnerability in External Authentication Provider Flow

Vulnerability

An open redirect vulnerability has been identified in Devolutions Server within the external authentication provider flow. This issue allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain by using a crafted login link. The vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0, as well as all versions prior to 2025.3.20.0.

Impact

Exploitation of this vulnerability could lead to unauthorized redirection of users to malicious websites, potentially causing phishing or other social engineering attacks.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or 2025.3.22.0 or higher.

Added: May 26, 2026, 3:37 PM
Updated: May 26, 2026, 3:37 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.2
exploitability
6.2
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.