Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.
2025-06-05T14:15:33.177
2025-07-02T14:36:11.027
Analyzed
CVSSv3.1: 6.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | devolutions | devolutions_server | < 2025.1.9.0 | Yes |