CVE-2026-4924
8.2Devolutions · Devolutions Server
A vulnerability in Devolutions Server allows authenticated users to bypass multifactor authentication by reusing partially authenticated session tokens.
Executive summary
A critical authentication bypass vulnerability in Devolutions Server 2026.1.11 and earlier allows attackers with valid credentials to circumvent multifactor authentication controls.
Vulnerability
This flaw involves improper authentication (CWE-1390) within the two-factor authentication feature, where a remote attacker who possesses valid primary credentials can reuse a partially authenticated session token to bypass 2FA requirements.
Business impact
The ability to bypass multifactor authentication significantly undermines the security posture of the Devolutions Server environment. With a CVSS score of 8.2, this vulnerability poses a high risk, as it allows an attacker to escalate their access or impersonate legitimate users despite secondary security controls. Such unauthorized access can lead to the compromise of sensitive administrative credentials, data exfiltration, and potential lateral movement within the network.
Remediation
Immediate Action: Review the Devolutions security advisory (DEVO-2026-0010) and apply the latest security updates provided by the vendor as soon as they are made available.
Proactive Monitoring: Audit application access logs for unusual session activity or multiple authentication attempts that do not align with standard user behavior.
Compensating Controls: Ensure that session timeouts are strictly enforced and consider implementing additional network-level access controls to restrict access to the management interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high severity of this authentication bypass, organizations should treat this as a priority item. While no public exploit currently exists, the ability to negate multifactor authentication is a high-value target for threat actors. Administrators must monitor the Devolutions security portal for the immediate release of a patch and prepare for an emergency deployment cycle to secure the affected instances.