Executive brief
Devolutions Server, a platform for managing remote connections and privileged access, contains a security flaw in its multi-factor authentication (MFA) system. If an attacker already knows a user's password, they can bypass the secondary security layer (MFA) after that user reconfigures their authentication settings. This could lead to unauthorized access to sensitive corporate credentials and remote systems managed by the server.
Technical details
An authentication bypass vulnerability (CWE-305) exists in Devolutions Server due to improper handling of factor key states within the MFA management feature. The vulnerability is triggered when a user reconfigures their multi-factor authentication settings, at which point the system fails to correctly validate or invalidate the state of authentication keys. An attacker who has already obtained a target user's primary password can exploit this flaw over the network to bypass MFA requirements. This issue affects Devolutions Server versions 2026.1.6.0 through 2026.1.16.0. Users are advised to upgrade to version 2026.1.19.0 or higher to remediate the risk.
Affected products
- Devolutions Server 2026.1.6.0 through 2026.1.16.0
Timeline
- 2026-05-21: advisory: Initial publication of DEVO-2026-0013 by Devolutions
- 2026-05-22: disclosed: CVE-2026-9047 published to NVD