Improper Access Control in Devolutions Server Affects Multi-Factor Authentication
CVE-2026-4925

5MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-4925?

An improper access control vulnerability in the multi-factor authentication (MFA) feature of Devolutions Server enables authenticated users to bypass administrative restrictions, allowing them to modify or remove their MFA configuration through specifically crafted requests. This behavior poses a risk to the security of user accounts and can be exploited if proper measures are not taken. Users are advised to review their configurations in versions 2026.1.6 to 2026.1.11 to mitigate the potential impact of this issue.

Affected Version(s)

Server 2026.1.6 <= 2026.1.11

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.