ZeroHour

CVE-2026-4829

CVSS 3.1
5.4 medium
EPSS
<1%p6
Published
()
Modified
Description

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

Vendors
devolutions
Products
devolutions server
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.