CVE-2025-12485
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step. This issue affects the following versions : Devolutions Server 2025.3.2.0 through 2025.3.5.0 Devolutions Server 2025.2.15.0 and earlier.
HIGH · CVSS 8.8
EPSS 0.00076
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0