CVE-2026-4927

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

History

03 Apr 2026, 19:14

Type Values Removed Values Added
First Time Devolutions
Devolutions devolutions Server
References () https://devolutions.net/security/advisories/DEVO-2026-0010 - () https://devolutions.net/security/advisories/DEVO-2026-0010 - Vendor Advisory
CPE cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

01 Apr 2026, 20:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

01 Apr 2026, 16:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 16:23

Updated : 2026-04-03 19:14


NVD link : CVE-2026-4927

Mitre link : CVE-2026-4927

CVE.ORG link : CVE-2026-4927


JSON object : View

Products Affected

devolutions

  • devolutions_server
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data