CVE-2026-105485: Medium severity Devolutions Devolutions Server vulnerability
Published Oct 6, 2026
·Updated
Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured device verification link by an authenticated victim.
Affected Software
1 affected component
Devolutions Devolutions Server<=2026.3.7.0
Event History
Oct 6, 2026
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker obtain to exploit this issue?
The attacker needs a captured OAuth device verification link and must get an authenticated victim to replay that link. Successful exploitation can allow takeover of the victim's account.
2
Which deployments are affected?
Devolutions Server versions 2026.3.7.0 and earlier are affected. The issue is remotely exploitable through the OAuth device authorization flow.