authentication in the two-factor authentication (2FA) feature in
Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid
credentials to bypass multifactor authentication and gain unauthorized
access to the victim account via reuse of a partially authenticated
session token.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0010 |
|
Tue, 07 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Devolutions Server 2FA bypass allows unauthorized account access |
Fri, 03 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Devolutions devolutions Server
|
|
| CPEs | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devolutions devolutions Server
|
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Devolutions Server 2FA bypass allows unauthorized account access | |
| First Time appeared |
Devolutions
Devolutions server |
|
| Vendors & Products |
Devolutions
Devolutions server |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially authenticated session token. | |
| Weaknesses | CWE-1390 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-04-01T20:19:57.967Z
Reserved: 2026-03-26T18:13:06.159Z
Link: CVE-2026-4924
Updated: 2026-04-01T20:18:38.655Z
Status : Analyzed
Published: 2026-04-01T16:23:51.657
Modified: 2026-04-03T19:22:06.100
Link: CVE-2026-4924
No data.
OpenCVE Enrichment
Updated: 2026-04-07T08:07:35Z