MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0035

Devolutions Server is affected by multiple vulnerabilities.

Affected Products

Devolutions Server
2026.3.7.0 and earlier

Change Log

Initial publication - 2026-10-06

Account takeover via replayable Azure AD login-session token

7.6 High - CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured login-session token exposed in a redirect URL.

CVE(s)

CVE-2026-9226

Remediation and Workarounds

Upgrade to Devolutions Server 2026.3.8.0 or higher, or 2026.2.19.0 or higher.

Account takeover via cross-site request forgery in device authorization

7.4 High - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured device verification link by an authenticated victim.

CVE(s)

CVE-2026-105485

Remediation and Workarounds

Upgrade to Devolutions Server 2026.3.8.0 or higher, or 2026.2.19.0 or higher.

Missing authorization on global vault contacts and folders

6.0 Medium - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Missing authorization in the global vault in Devolutions Server 2026.3.7.0 and earlier allows an authenticated user with only the global vault view permission to modify and delete global contact and folder entries.

CVE(s)

CVE-2026-105488

Remediation and Workarounds

Upgrade to Devolutions Server 2026.3.8.0 or higher, or 2026.2.19.0 or higher.