CVE-2025-12485: Devolutions Server

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step. This issue affects the following versions : * Devolutions Server 2025.3.2.0 through 2025.3.5.0 * Devolutions Server 2025.2.15.0 and earlier

Affected products

  • Devolutions Devolutions Server: before 2025.2.17.0 (fixed in 2025.2.17.0); from 2025.3.2.0, before 2025.3.6.0 (fixed in 2025.3.6.0)

Published 2025-11-06. Last modified 2026-10-07.