CVE-2026-105485
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in Devolutions Server via OAuth Device Flow

Vulnerability report for CVE-2026-105485, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Devolutions Inc.

Description

Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured device verification link by an authenticated victim.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Devolutions Server 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-294 A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in Devolutions Server versions 2026.3.7.0 and earlier. It affects the OAuth device authorization flow, allowing a remote attacker to take over a user's account by replaying a captured device verification link if an authenticated victim accesses it.

Impact Analysis

If you use Devolutions Server 2026.3.7.0 or earlier, an attacker could exploit this to gain unauthorized access to your account by intercepting and replaying a verification link. This could lead to data theft, unauthorized actions, or full account compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. Organizations may face compliance breaches, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately update Devolutions Server to a version newer than 2026.3.7.0 to patch the authentication bypass flaw in the OAuth device authorization flow.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105485. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart