---
id: CVE-2026-9226
title: >-
  Authentication bypass in the Azure AD external login flow in Devolutions
  Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's
  account via replay of a captured login-session token exposed in a redirect
  URL.
summary: >-
  Authentication bypass in the Azure AD external login flow in Devolutions
  Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's
  account via replay of a captured login-session token exposed in a redirect
  URL.
severity: none
cwe:
  - CWE-294
vendor: Devolutions
product: Server
affected:
  - Server < 2026.3.8
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T19:58:37.060'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9226'
references:
  - url: 'https://devolutions.net/security/advisories/DEVO-2026-0035/'
    label: security@devolutions.net
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T19:13:33.943Z'
---

## Overview

Authentication bypass in the Azure AD external login flow in Devolutions Server 2026.3.7.0 and earlier allows a remote attacker to take over a user's account via replay of a captured login-session token exposed in a redirect URL.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
