National Cyber Warfare Foundation (NCWF)

CVE-2026-5175


0 user ratings
2026-03-30 00:00:00
milo
CVEs

 - archive -- 

CVE-2026-5175

Date: 2026-03-30

CVE Link

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests. 







This issue affects Server: from 2026.1.6 through 2026.1.11.



References:



Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
CVEs



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.