CVE-2026-3224: Critical severity Microsoft Entra ID vulnerability
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3224?
CVE-2026-3224 is considered a critical vulnerability as it allows unauthenticated access to arbitrary user accounts through JWT forgery.
How do I fix CVE-2026-3224?
To fix CVE-2026-3224, upgrade to Devolutions Server version 2025.3.15.1 or later and ensure Microsoft Entra ID is also updated.
What is the impact of CVE-2026-3224?
The impact of CVE-2026-3224 is that an unauthenticated attacker can gain unauthorized access to user accounts and sensitive information.
Is my system vulnerable to CVE-2026-3224?
If you are using Microsoft Entra ID or Devolutions Server versions earlier than 2025.3.15.0, your system is vulnerable to CVE-2026-3224.
Who is affected by CVE-2026-3224?
Organizations using Microsoft Entra ID or Devolutions Server versions up to 2025.3.15.0 are affected by CVE-2026-3224.