CVE-2026-9245: Input Validation
Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a crafted login link.
This issue affects :
Devolutions Server 2026.1.6.0 through 2026.1.16.0 Devolutions Server 2025.3.20.0 and earlier
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to Devolutions Server authentication and management endpoints to trusted IP ranges (firewall/ACL) to reduce exposure of the login flow to untrusted/unverified clients.
- Compensating control
Deploy WAF/IDS rules to validate and block unexpected/unsafe redirect parameters on login endpoints and to detect or block crafted login links that attempt redirection to attacker-controlled domains.
- Compensating control
Temporarily disable or avoid using the external authentication provider login link flow (or refrain from sending clickable external login links) until the vendor provides a security fix.
- Operational
Monitor web and authentication logs for suspicious login link usage or unexpected external redirects and investigate/alert on anomalies; review recent logs for possible exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9245?
CVE-2026-9245 has a risk score of 35, indicating a moderate severity vulnerability.
How do I fix CVE-2026-9245?
To fix CVE-2026-9245, update Devolutions Server to the latest version beyond 2026.1.16.0.
What is the impact of CVE-2026-9245?
CVE-2026-9245 allows an unauthenticated remote attacker to redirect victims to a malicious domain using a crafted login link.
Which versions of Devolutions Server are affected by CVE-2026-9245?
CVE-2026-9245 affects Devolutions Server versions from 2026.1.6.0 to 2026.1.16.0.
What type of vulnerability is CVE-2026-9245 classified as?
CVE-2026-9245 is classified as an Input Validation vulnerability.