CVE-2026-4828: High severity Devolutions Devolutions Server vulnerability
Published Apr 1, 2026
·Updated
Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request.
Affected Software
3 affected components
Devolutions Devolutions Server<=2026.1.11
Devolutions Devolutions Server<2025.3.18.0
Devolutions Devolutions Server>=2026.1.1.0<2026.1.12.0
Event History
Apr 1, 2026
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
DescriptionWeakness
Data Sourced
via NVD·04:23 PM
DescriptionSeverityWeaknessAffected Software