CVE-2026-9047: High severity Devolutions Devolutions Server vulnerability
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors.
This issue affects :
Devolutions Server 2026.1.6.0 through 2026.1.16.0
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9047?
CVE-2026-9047 has a severity score of 55, indicating a medium risk level.
How do I fix CVE-2026-9047?
To fix CVE-2026-9047, update your Devolutions Server to the latest version that addresses this vulnerability.
What is the impact of CVE-2026-9047?
CVE-2026-9047 allows an attacker with knowledge of a user's password to bypass multi-factor authentication after reconfiguration.
Who is affected by CVE-2026-9047?
CVE-2026-9047 affects users of the Devolutions Server software that utilize multi-factor authentication.
What does CVE-2026-9047 involve?
CVE-2026-9047 involves improper handling of factor key state in the multi-factor authentication management feature.