Medium
CVE-2026-5175
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti…
High
CVE-2026-4828
Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att…
Medium
CVE-2026-4829
Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an…
High
CVE-2026-4924
Improper
authentication in the two-factor authentication (2FA) feature in
Devolutions Server 2026.1.11 and earlier all…
Medium
CVE-2026-4925
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra…
Medium
CVE-2026-4927
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi…