CVE-2026-4927

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-01 16:23

Updated : 2026-06-17 10:57


NVD link : CVE-2026-4927

Mitre link : CVE-2026-4927

CVE.ORG link : CVE-2026-4927


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data