Vulnerability Database

315,294

Total vulnerabilities in the database

CVE-2024-4846

Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.

  • Published: Jun 25, 2024
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-4846
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.3
  • AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CWEs: