Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step.
This issue affects the following versions :
Devolutions Server 2025.2.15.0 and earlier
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Devolutions_server | Devolutions | * | 2025.2.17.0 (excluding) |
| Devolutions_server | Devolutions | 2025.3.2.0 (including) | 2025.3.6.0 (excluding) |