CVE-2026-3224

CRITICAL

Devolutions Server <2025.3.15.0 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-3224. PoCs published by HiZisec.

AI-analyzed exploit summary The repository lacks actual exploit code and instead directs users to an external download link (tinyurl.com). The README provides minimal technical details about the vulnerability and reads more like a sales pitch.

Description

Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).

Exploits (1)

nomisec SUSPICIOUS
by HiZisec · poc
https://github.com/HiZisec/CVE-2026-3224-Exploit

The repository lacks actual exploit code and instead directs users to an external download link (tinyurl.com). The README provides minimal technical details about the vulnerability and reads more like a sales pitch.

Classification
Suspicious 95%
Attack Type
Auth Bypass
Complexity
Theoretical
Reliability
Theoretical
Target: Devolutions Server 2025.3.15.0 and earlier with Microsoft Entra ID (Azure AD) authentication
No auth needed
Prerequisites: tenant-id · target-user-email
devstral-2 · analyzed Mar 05, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 23.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (1)
devolutions/devolutions_server < 2025.3.16.0
Published Mar 03, 2026
Tracked Since Mar 04, 2026