PT-2026-29537 · Devolutions · Server

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-4829

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-4829

Affected Products

Server