Threat Intel

v0.1

← CVEs

CVE-2026-3224

CRIT 9.8
Published
2026-03-03
Last Modified
2026-03-05
Affected Apps
2
Affected Devices
2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).
References 1