Devolutions Server 2026.3.7.0 及更早版本中,Azure AD 外部登录流程存在身份验证绕过漏洞。远程攻击者可通过重放捕获到的、暴露在重定向 URL 中的登录会话令牌,劫持用户账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Devolutions | Server | < 2026.3.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Devolutions | Server | 0 ~ 2026.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105485 | Devolutions Server认证绕过漏洞(2026.3.7.0及更早版本) | |
| CVE-2026-105488 | Devolutions Server 2026.3.7.0缺少授权致数据修改删除 |
No comments yet