在 Devolutions Server 2026.3.7.0 及更早版本中,OAuth 设备授权流程存在身份验证绕过漏洞,允许远程攻击者通过重放被认证受害者捕获的设备验证链接,从而接管用户账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Devolutions | Server | < 2026.3.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Devolutions | Server | 0 ~ 2026.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105488 | Devolutions Server 2026.3.7.0缺少授权致数据修改删除 | |
| CVE-2026-9226 | Devolutions Server认证绕过漏洞 |
No comments yet