CVE-2026-3224
EUVD-2026-933803.03.2026, 22:16
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| devolutions | devolutions_server | 𝑥 < 2025.3.16.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration