CVE-2026-4829

MEDIUM

Devolutions Server <=2026.1.11 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

Scores

CVSS v3 5.4
EPSS 0.0004
EPSS Percentile 11.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (2)
devolutions/devolutions_server < 2026.1.12.0
Devolutions/Server < 2026.1.11
Published Apr 01, 2026
Tracked Since Apr 01, 2026