Vulnerability Bulletins |
CVE-2026-3224 |
|
| Affected software | MICROSOFT |
| Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT). | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-3224 | |






