Description
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. The problem occurs when DVLS encounters an invalid default MFA value.
Published: 2026-07-06
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Devolutions Server 2026.2.9.0 contains a logic flaw that disables the required multi‑factor authentication when an unexpected default MFA value is detected. An attacker who already has a valid user account can log in using the normal password and immediately gain access without completing the second factor, effectively bypassing MFA. This allows full compromise of any account that successfully authenticates a password, potentially giving the attacker unrestricted access to the server. The flaw is due to improper enforcement of the MFA requirement, a classic authentication bypass associated with CWE‑287.

Affected Systems

The vulnerability is present only in Devolutions Server 2026.2.9.0 when the application is configured with the system's default MFA settings. Earlier or later major releases are not reported as affected. Organizations that have not applied the vendor’s patch or newer release that corrects the MFA enforcement logic are vulnerable. The flaw requires no elevated privileges beyond a compromised user credential.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity and a high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that, as of the latest data, exploitation is unlikely, but the fault remains present. The vulnerability is not listed in the CISA KEV catalog. If an attacker can compromise a valid user account, the bypass allows them to completely skip MFA, so the risk is high for any environment that relies on MFA as a critical defense. The risk is mitigated if MFA is enforced at the network or application level beyond the server itself.

Generated by OpenCVE AI on July 22, 2026 at 12:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑published patch or upgrade to a newer release of Devolutions Server that restores proper MFA enforcement.
  • Reconfigure the MFA settings to reject invalid default values and enforce MFA on all login attempts.
  • Disable or remove default MFA configuration paths that allow the logic flaw to be triggered.
  • Monitor authentication logs for logins that skip MFA and investigate any suspicious activity.

Generated by OpenCVE AI on July 22, 2026 at 12:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Devolutions Server MFA Enforced Logic Flaw Allows Authentication Bypass
Weaknesses CWE-287

Fri, 17 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Devolutions Server MFA Enforced Logic Flaw Allows Authentication Bypass
Weaknesses CWE-287

Tue, 14 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Devolutions Server MFA Enforcement Bypass
Weaknesses CWE-284
CWE-639

Mon, 13 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Devolutions Server MFA Enforcement Bypass
Weaknesses CWE-284
CWE-639

Sun, 12 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Improper MFA Enforcement Allows Authentication Bypass in Devolutions Server
Weaknesses CWE-287

Sat, 11 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper MFA Enforcement Allows Authentication Bypass in Devolutions Server
Weaknesses CWE-287

Fri, 10 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title MFA Bypass Allows Authentication Without Second Factor in Devolutions Server
Weaknesses CWE-287

Fri, 10 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title MFA Bypass Allows Authentication Without Second Factor in Devolutions Server
Weaknesses CWE-287

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title MFA Enforcement Bypass Allows Authentication Without Multi‑Factor Confirmation in Devolutions Server 2026.2.9.0
Weaknesses CWE-285

Wed, 08 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title MFA Enforcement Bypass Allows Authentication Without Multi‑Factor Confirmation in Devolutions Server 2026.2.9.0
Weaknesses CWE-285

Wed, 08 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title MFA Enforcement Bypass in Devolutions Server 2026.2.9.0
Weaknesses CWE-285

Tue, 07 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title MFA Enforcement Bypass in Devolutions Server 2026.2.9.0
Weaknesses CWE-285

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. The problem occurs when DVLS encounters an invalid default MFA value.
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-07-09T15:01:21.700Z

Reserved: 2026-07-03T00:08:05.267Z

Link: CVE-2026-14536

cve-icon Vulnrichment

Updated: 2026-07-07T14:00:31.458Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T12:45:02Z

Weaknesses

No weakness.