CVE-2026-5175: Medium severity Devolutions Devolutions Server vulnerability
Published Apr 1, 2026
·Updated
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests.
This issue affects Server: from 2026.1.6 through 2026.1.11.
Affected Software
2 affected components
Devolutions Devolutions Server>=2026.1.6<=2026.1.11
Devolutions Devolutions Server>=2026.1.6.0<2026.1.12.0
Event History
Apr 1, 2026
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
DescriptionWeakness
Data Sourced
via NVD·04:23 PM
DescriptionSeverityWeaknessAffected Software
Feb 13, 58282
Event
via FIRST·03:39 PM