6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request.
This issue affects Server: from 2026.1.6 through 2026.1.11.
This issue affects Server: from 2026.1.6 through 2026.1.11.
Basic Information
ID
CVE-2026-4927
Source
DEVOLUTIONS
Published
Apr 1, 2026 at 14:54
Modified
Apr 1, 2026 at 19:26
Affected Product
Vendor
Devolutions
Product
Server
Version
2026.1.6
Affected Versions
Devolutions Server 2026.1.6