CVE-2026-4927: Devolutions Server

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

Affected products

  • Devolutions Devolutions Server: from 2026.1.6.0, before 2026.1.12.0 (fixed in 2026.1.12.0)

Published 2026-04-01. Last modified 2026-06-17.