
CVE-2026-5175 Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MF… https://www.cve.org/CVERecord?id=CVE-2026-5175
Post summary
The post discloses an improper access‑control flaw in Devolutions Server’s MFA management API that lets authenticated users delete their own MFA configuration, but makes no mention of PoC, exploit code, active attacks, or patches.
