Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially authenticated session token.
History

Tue, 07 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Title Devolutions Server 2FA bypass allows unauthorized account access

Fri, 03 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions devolutions Server
CPEs cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Vendors & Products Devolutions devolutions Server

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title Devolutions Server 2FA bypass allows unauthorized account access
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially authenticated session token.
Weaknesses CWE-1390
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published: 2026-04-01T14:50:51.684Z

Updated: 2026-04-01T20:19:57.967Z

Reserved: 2026-03-26T18:13:06.159Z

Link: CVE-2026-4924

cve-icon Vulnrichment

Updated: 2026-04-01T20:18:38.655Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-01T16:23:51.657

Modified: 2026-04-03T19:22:06.100

Link: CVE-2026-4924

cve-icon Redhat

No data.