CVE-2026-4925
Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request.
This issue affects Server: from 2026.1.6 through 2026.1.11.
This issue affects Server: from 2026.1.6 through 2026.1.11.
Vendor
Product
CWE
Yayın Tarihi
2026-04-01 16:23:51
Güncelleme
2026-04-03 19:14:36
Source Identifier
security@devolutions.net
KEV Date Added
-