Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0005/ |
|
Fri, 17 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass via Forged JSON Web Token in Devolutions Server |
Thu, 05 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions devolutions Server
|
|
| CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devolutions devolutions Server
|
Wed, 04 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 04 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions
Devolutions server |
|
| Vendors & Products |
Devolutions
Devolutions server |
Tue, 03 Mar 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT). | |
| Weaknesses | CWE-287 | |
| References |
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-03-04T14:43:18.563Z
Reserved: 2026-02-25T18:56:18.991Z
Link: CVE-2026-3224
Updated: 2026-03-04T14:43:15.515Z
Status : Analyzed
Published: 2026-03-03T22:16:29.523
Modified: 2026-03-05T15:05:49.170
Link: CVE-2026-3224
No data.
OpenCVE Enrichment
Updated: 2026-04-17T13:30:19Z