CVE-2026-4829
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.
Affected (1)
Products: Devolutions: Devolutions Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2026.1.12.0 |
References (1)
Source: security@devolutions.net
Vendor Advisory
Timeline
No history available yet.