Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request.
This issue affects Server: from 2026.1.6 through 2026.1.11.
References
| Link | Resource |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0010 | Vendor Advisory |
Configurations
History
03 Apr 2026, 19:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Devolutions
Devolutions devolutions Server |
|
| References | () https://devolutions.net/security/advisories/DEVO-2026-0010 - Vendor Advisory | |
| CPE | cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* |
01 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
01 Apr 2026, 16:23
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 16:23
Updated : 2026-04-03 19:14
NVD link : CVE-2026-4927
Mitre link : CVE-2026-4927
CVE.ORG link : CVE-2026-4927
JSON object : View
Products Affected
devolutions
- devolutions_server
CWE
CWE-201
Insertion of Sensitive Information Into Sent Data
