Vulnerability Description
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Devolutions | Devolutions Server | >= 2026.1.6.0, < 2026.1.19.0 |
Related Weaknesses (CWE)
References
- https://devolutions.net/security/advisories/DEVO-2026-0013/Vendor Advisory
FAQ
What is CVE-2026-9047?
CVE-2026-9047 is a vulnerability with a CVSS score of 7.6 (HIGH). Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-fact...
How severe is CVE-2026-9047?
CVE-2026-9047 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-9047?
Check the references section above for vendor advisories and patch information. Affected products include: Devolutions Devolutions Server.