CVE-2026-4925 — Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) — CVE Database · The Intelligence Room