Junglewise Threat Intelligence

CVE-2026-9245: Devolutions Server open redirect in external authentication flow

CVE-2026-9245 · Severity: medium · CVSS 5 · Published 2026-05-22

Technologies: Devolutions Server. Vendors: Devolutions.

Executive brief

Devolutions Server, a centralized platform for managing remote connections and privileged access, is vulnerable to an open redirect flaw. An attacker can create a malicious login link that, when clicked by a user, redirects them from the legitimate server to a fraudulent website. This could be used in phishing campaigns to steal user credentials or distribute malware by mimicking the organization's official login portal.

Technical details

An open redirect vulnerability (CWE-601) exists in Devolutions Server due to improper input validation within the external authentication provider flow. An unauthenticated remote attacker can exploit this by crafting a specific login URL that includes a malicious redirection target. While the attack requires user interaction (clicking the link), it allows the attacker to leverage the trusted domain of the Devolutions Server to facilitate phishing or credential harvesting. The issue is resolved in Devolutions Server versions 2026.1.19.0 and 2025.3.22.0.

Affected products

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0; 2025.3.20.0 and earlier

Timeline

  • 2026-05-21: advisory: Initial publication by Devolutions
  • 2026-05-22: disclosed: NVD publication date

References