CVE-2026-4829: Devolutions Server

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

Affected products

  • Devolutions Devolutions Server: before 2026.1.12.0 (fixed in 2026.1.12.0)

Published 2026-04-01. Last modified 2026-06-17.