Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026
Devolutions CVEs
19 high and critical vulnerabilities covered by CVE Brief since 2025-07-23, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
16 CVEs in the last 12 months
Products
- Server12
- PowerShell Universal4
- Hub Reporting Service1
- Remote Desktop Manager1
- Devolutions Server1
5 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Improper authentication in the OAuth login functionality in Devolutions Server 2026
Improper certificate validation in Devolutions Hub Reporting Service 2025
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the u...
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to...
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low...
Devolutions Server 2026.2.4.0 through 2026.2.9.0 fails to enforce mandatory multi-factor authentication (MFA) policies when encountering invalid defau...
Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules
Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due...
Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure me...
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via br...
Improper privilege management during pre-MFA cookie handling in Devolutions Server 2025
Improper authorization in the temporary access workflow of Devolutions Server 2025
Improper certificate validation when connecting to gateways in Devolutions Server 2025