CVE-2026-3224
03.03.2026, 22:16
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration