Input Validation Vulnerability in Devolutions Server Affects User Authentication
CVE-2026-9245

5MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 May 2026

What is CVE-2026-9245?

An improper input validation issue exists in Devolutions Server's external authentication provider flow that allows unauthenticated remote attackers to exploit this vulnerability. Attackers can craft malicious login links that redirect victims to domains controlled by the attacker, posing significant risks to the security of sensitive information. Users of affected versions should apply patches and mitigations promptly to avoid potential exploits.

Affected Version(s)

Server 2026.1.6.0 <= 2026.1.16.0

Server 0 <= 2025.3.20.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.