CVE-2026-4925: Medium severity Devolutions Devolutions Server vulnerability
Published Apr 1, 2026
·Updated
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request.
This issue affects Server: from 2026.1.6 through 2026.1.11.
Affected Software
2 affected components
Devolutions Devolutions Server>=2026.1.6<=2026.1.11
Devolutions Devolutions Server>=2026.1.6.0<2026.1.12.0
Event History
Apr 1, 2026
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionWeakness
Data Sourced
via NVD·04:23 PM
DescriptionSeverityWeaknessAffected Software
Aug 1, 58235
Event
via FIRST·01:38 AM