CVE-2026-4829

Published Apr 1, 2026

Last updated 14 days ago

Overview

Description
Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.
Source
security@devolutions.net
NVD status
Analyzed
Products
devolutions_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.4
Impact score
2.5
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

security@devolutions.net
CWE-287

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.