CVE-2026-14536: High severity Devolutions Devolutions Server vulnerability
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. The problem occurs when DVLS encounters an invalid default MFA value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14536?
The severity of CVE-2026-14536 is categorized as high, with a CVSS score of 8.8.
How do I fix CVE-2026-14536?
To fix CVE-2026-14536, it is recommended to update to Devolutions Server version 2026.2.9.1 or later.
What is the impact of CVE-2026-14536?
CVE-2026-14536 allows attackers with valid user credentials to bypass multi-factor authentication requirements, compromising the security of user accounts.
Who is affected by CVE-2026-14536?
CVE-2026-14536 affects users of Devolutions Server version 2026.2.9.0 and earlier that have implemented mandatory multi-factor authentication.
Is there a workaround for CVE-2026-14536?
Currently, no specific workaround for CVE-2026-14536 is available, so the best course of action is to apply the recommended update.