Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request.
This issue affects Server: from 2026.1.6 through 2026.1.11.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0010 |
|
History
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11. | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-04-01T19:26:56.487Z
Reserved: 2026-03-26T18:39:49.096Z
Link: CVE-2026-4927
Updated: 2026-04-01T19:26:52.703Z
Status : Received
Published: 2026-04-01T16:23:51.870
Modified: 2026-04-01T20:16:29.220
Link: CVE-2026-4927
No data.
OpenCVE Enrichment
No data.