CVE-2026-4927

Published: Apr 01, 2026 Last Modified: Apr 01, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request.

This issue affects Server: from 2026.1.6 through 2026.1.11.

201

Insertion of Sensitive Information Into Sent Data

Draft
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Files Or Directories Read Memory Read Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
https://devolutions.net/security/advisories/DEVO-2026-0010