HomeDefault status
unaffected
2026.1.6.0 (custom)
affected
Description
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0
Problem types
CWE-305 Authentication bypass by primary weakness
Product status
2026.1.6.0 (custom)
References
devolutions.net/security/advisories/DEVO-2026-0013/