Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier
Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request.
This issue affects :
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 31.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 31.00 |
VPI formula vpi-v1