Devolutions Server
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*
- >= 2026.1.6.0, <= 2026.1.16.0
- <= 2025.3.20.0
An open redirect vulnerability has been identified in Devolutions Server within the external authentication provider flow. This issue allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain by using a crafted login link. The vulnerability affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0, as well as all versions prior to 2025.3.20.0.
Exploitation of this vulnerability could lead to unauthorized redirection of users to malicious websites, potentially causing phishing or other social engineering attacks.
Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or 2025.3.22.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.