Bypass Vulnerability in Two-Factor Authentication for Devolutions Server
CVE-2026-4924
8.2HIGH
What is CVE-2026-4924?
The two-factor authentication (2FA) feature in Devolutions Server versions up to 2026.1.11 has a vulnerability that allows remote attackers, who possess valid credentials, to bypass multifactor authentication. This occurs due to improper authentication processes that permit the reuse of a partially authenticated session token, facilitating unauthorized access to user accounts.
Affected Version(s)
Server 0 <= 2026.1.11
