Description
Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.
Published: 2026-09-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Man-in-the-Middle Credential Theft
Action: Apply Update
AI Analysis

Impact

Devolutions Server versions 2026.2.16 and earlier perform inadequate certificate validation for LDAPS connections to Active Directory. This flaw, classified as CWE‑295, permits an attacker who can position themselves on the same network to present a forged domain controller certificate and capture privileged directory service credentials that the server transmits over LDAPS. The result is direct exposure of confidential credentials and potential compromise of related services.

Affected Systems

The vulnerability affects Devolutions Server 2026.2.16 and all earlier releases. No other vendors or supporting products are mentioned in the CNA data.

Risk and Exploitability

Because the attacker must be on the same network and successfully intercept LDAPS traffic, the exploitation requires network proximity but imposes no special user permissions. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, so public exploitation evidence is currently unknown. Nevertheless, the severity of credential theft warrants immediate attention, especially in environments where LDAPS traffic is exposed to untrusted hosts.

Generated by OpenCVE AI on September 17, 2026 at 07:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Devolutions Server release that includes the LDAPS certificate validation fix.
  • Configure LDAPS to enforce strict certificate validation, rejecting self‑signed or untrusted certificates.
  • Limit exposure of LDAPS traffic by applying firewall rules or VLAN segmentation to protect communication between the Devolutions Server and Active Directory.

Generated by OpenCVE AI on September 17, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Allowing LDAPS MITM Credential Interception in Devolutions Server

Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Allowing LDAPS MITM Credential Interception in Devolutions Server

Tue, 15 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.
Weaknesses CWE-295
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-09-15T19:14:33.240Z

Reserved: 2026-06-25T13:10:27.255Z

Link: CVE-2026-13327

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:07.627

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-13327

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T07:45:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation