Impact
Devolutions Server 2026.2.9.0 contains a logic flaw that disables the required multi‑factor authentication when an unexpected default MFA value is detected. An attacker who already has a valid user account can log in using the normal password and immediately gain access without completing the second factor, effectively bypassing MFA. This allows full compromise of any account that successfully authenticates a password, potentially giving the attacker unrestricted access to the server. The flaw is due to improper enforcement of the MFA requirement, a classic authentication bypass associated with CWE‑287.
Affected Systems
The vulnerability is present only in Devolutions Server 2026.2.9.0 when the application is configured with the system's default MFA settings. Earlier or later major releases are not reported as affected. Organizations that have not applied the vendor’s patch or newer release that corrects the MFA enforcement logic are vulnerable. The flaw requires no elevated privileges beyond a compromised user credential.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity and a high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that, as of the latest data, exploitation is unlikely, but the fault remains present. The vulnerability is not listed in the CISA KEV catalog. If an attacker can compromise a valid user account, the bypass allows them to completely skip MFA, so the risk is high for any environment that relies on MFA as a critical defense. The risk is mitigated if MFA is enforced at the network or application level beyond the server itself.
OpenCVE Enrichment