Description
Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests. This issue affects Server: from 2026.1.6 through 2026.1.11.
INFO
Published Date :
2026-04-01T15:04:22.130Z
Last Modified :
2026-04-01T20:12:09.411Z
Source :
DEVOLUTIONS
AFFECTED PRODUCTS
The following products are affected by CVE-2026-5175 vulnerability.
| Vendors | Products |
|---|---|
| Devolutions |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-5175.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact