CVE-2026-4927

Published Apr 1, 2026

Last updated 14 days ago

Overview

Description
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.
Source
security@devolutions.net
NVD status
Analyzed
Products
devolutions_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

security@devolutions.net
CWE-201

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.