Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9047

Опубликовано: 22 мая 2026
Источник: nvd
CVSS3: 7.6
EPSS Низкий

Описание

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors.

This issue affects :

  • Devolutions Server 2026.1.6.0 through 2026.1.16.0

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*
Версия от 2026.1.6.0 (включая) до 2026.1.19.0 (исключая)

EPSS

Процентиль: 24%
0.00319
Низкий

7.6 High

CVSS3

Дефекты

CWE-305

Связанные уязвимости

CVSS3: 7.6
github
2 месяца назад

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass the user's multi-factor authentication after the user reconfigures their factors. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0

EPSS

Процентиль: 24%
0.00319
Низкий

7.6 High

CVSS3

Дефекты

CWE-305