Junglewise Threat Intelligence

CVE-2026-14536: Devolutions Server MFA bypass via invalid default MFA value

CVE-2026-14536 · Severity: info · CVSS 7.6 · Published 2026-07-06

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and privileged credentials, contains a flaw that allows users to bypass mandatory multi-factor authentication (MFA). If an attacker obtains a user's primary password, they can log in to the system without providing the required second form of verification. This could lead to unauthorized access to sensitive corporate credentials and remote management tools.

Technical details

An authentication bypass vulnerability exists in Devolutions Server (DVLS) due to improper enforcement of mandatory multi-factor authentication (MFA) policies. The vulnerability is triggered when the application encounters an invalid default MFA value, causing it to fail open and allow authentication to proceed with only primary credentials. An attacker with valid network-reachable user credentials can exploit this to bypass the 'MFA Required' policy. The issue affects versions 2026.2.4.0 through 2026.2.9.0 and is resolved in version 2026.2.11.0.

Affected products

  • Devolutions Server 2026.2.4.0 through 2026.2.9.0

Timeline

  • 2026-07-06: disclosed
  • 2026-07-06: advisory

References