CVE-2026-4828

8.2

Devolutions · Devolutions Server

A vulnerability in Devolutions Server allows authenticated users to bypass multi-factor authentication via a crafted OAuth login request.

Executive summary

A critical authentication bypass vulnerability in Devolutions Server 2026.1.11 and earlier allows attackers with valid credentials to circumvent multi-factor authentication, posing a severe risk to account security.

Vulnerability

This flaw involves improper authentication (CWE-1390) within the OAuth login functionality. It requires an attacker to possess valid credentials, after which they can bypass multi-factor authentication requirements through a crafted login request.

Business impact

Successful exploitation of this vulnerability permits unauthorized access to sensitive administrative or user accounts, effectively neutralizing the security benefits of multi-factor authentication. Given the CVSS score of 8.2, this represents a high-severity risk that could lead to significant data compromise or unauthorized administrative control over the Devolutions environment.

Remediation

Immediate Action: Update Devolutions Server to the latest available version beyond 2026.1.11 to patch the OAuth login flaw.

Proactive Monitoring: Review authentication and access logs for suspicious login patterns, particularly those originating from unexpected IP addresses or showing unusual OAuth activity.

Compensating Controls: Implement strict network access controls or VPN requirements to limit the exposure of the authentication portal while the patch is being deployed.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a substantial risk to identity security by undermining multi-factor authentication. Organizations should prioritize updating their Devolutions Server installations immediately to the latest patched version to ensure that MFA protections are correctly enforced and to prevent potential account takeovers.

More Devolutions CVEs

Sources