Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0035/ |
|
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 06 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication bypass OAuth device authorization flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured device verification link by an authenticated victim. | |
| Weaknesses | CWE-294 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-10-06T19:00:19.392Z
Reserved: 2026-10-05T15:02:53.149Z
Link: CVE-2026-105485
Updated: 2026-10-06T19:00:06.751Z
Status : Received
Published: 2026-10-06T19:17:40.960
Modified: 2026-10-06T19:17:40.960
Link: CVE-2026-105485
No data.
OpenCVE Enrichment
No data.
-
CWE-294
Authentication Bypass by Capture-replay