Description
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request.



This issue affects Server: from 2026.1.6 through 2026.1.11.
Published: 2026-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch Now
AI Analysis

Impact

An authenticated API in Devolutions Server allows users with user‑management privileges to retrieve other users’ one‑time password (OTP) keys, exposing the secrets that protect multi‑factor authentication. The vulnerability, classified as CWE‑201, compromises the confidentiality of MFA credentials and enables attackers who obtain such keys to perform account takeovers or bypass two‑factor protections. The attack does not directly grant code execution or denial of service, but it removes a critical layer of security.

Affected Systems

The flaw affects Devolutions Server versions 2026.1.6 through 2026.1.11. Users of these releases should verify whether they are running an impacted build and assess the presence of user‑management role assignments.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate to high severity. Because exploitation requires legitimate, privileged user access, the EPSS score is below 1 %, suggesting a low probability of widespread, automated attacks. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, compromised OTP keys can lead to full account compromise, so the risk remains substantial for any system where malicious or compromised privileged users exist.

Generated by OpenCVE AI on April 3, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Devolutions Server to version 2026.1.12 or later, or apply the vendor‑issued patch that corrects API access to OTP keys.
  • If an upgrade is not immediately possible, remove or restrict user‑management privileges for accounts that do not require them, thereby limiting the ability to request other users’ OTP keys.
  • Monitor audit logs for anomalous OTP key retrieval requests, and enforce strict logging of privileged actions.
  • Consider disabling or limiting the exposure of OTP keys through application configuration until a remediation is achieved.

Generated by OpenCVE AI on April 3, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Title MFA OTP Key Exposure via Authenticated API

Fri, 03 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions devolutions Server
CPEs cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Vendors & Products Devolutions devolutions Server

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Title MFA OTP Key Exposure via Authenticated API
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Devolutions Devolutions Server Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-04-01T19:26:56.487Z

Reserved: 2026-03-26T18:39:49.096Z

Link: CVE-2026-4927

cve-icon Vulnrichment

Updated: 2026-04-01T19:26:52.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-01T16:23:51.870

Modified: 2026-04-03T19:14:03.653

Link: CVE-2026-4927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-07T08:07:34Z

Weaknesses