Devolutions Server Password Change Bypass Vulnerability

Vulnerability

A vulnerability in Devolutions Server allows an attacker to change a user's password without providing the previous one, by sending a crafted password change request. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0, as well as all versions prior to 2025.3.20.0.

Impact

Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to unauthorized access to user accounts.

Remediation

Users are advised to upgrade to Devolutions Server version 2026.1.19.0 or higher, or version 2025.3.22.0 or higher.

Added: May 26, 2026, 3:34 PM
Updated: May 26, 2026, 3:34 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
7.4
remediation
7.7
relevance
9.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.