Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step.
This issue affects the following versions :
Devolutions Server 2025.2.15.0 and earlier
| Software | From | Fixed in |
|---|---|---|
| devolutions / devolutions_server | - | 2025.2.17.0 |
| devolutions / devolutions_server | 2025.3.2.0 | 2025.3.6.0 |