Security & compliance
Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0035
Devolutions Server is affected by multiple vulnerabilities.
Affected Products
Change Log
Initial publication - 2026-10-06
Account takeover via replayable Azure AD login-session token
7.6 High - CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured login-session token exposed in a redirect URL.
CVE(s)
CVE-2026-9226
Remediation and Workarounds
Upgrade to Devolutions Server 2026.3.8.0 or higher, or 2026.2.19.0 or higher.
Account takeover via cross-site request forgery in device authorization
7.4 High - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured device verification link by an authenticated victim.
CVE(s)
CVE-2026-105485
Remediation and Workarounds
Upgrade to Devolutions Server 2026.3.8.0 or higher, or 2026.2.19.0 or higher.
Missing authorization on global vault contacts and folders
6.0 Medium - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and earlier allows an authenticated user with only the global vault view permission to modify and delete global contact and folder entries.
CVE(s)
CVE-2026-105488
Remediation and Workarounds
Upgrade to Devolutions Server 2026.3.8.0 or higher, or 2026.2.19.0 or higher.