Impact
Devolutions Server versions 2026.2.16 and earlier perform inadequate certificate validation for LDAPS connections to Active Directory. This flaw, classified as CWE‑295, permits an attacker who can position themselves on the same network to present a forged domain controller certificate and capture privileged directory service credentials that the server transmits over LDAPS. The result is direct exposure of confidential credentials and potential compromise of related services.
Affected Systems
The vulnerability affects Devolutions Server 2026.2.16 and all earlier releases. No other vendors or supporting products are mentioned in the CNA data.
Risk and Exploitability
Because the attacker must be on the same network and successfully intercept LDAPS traffic, the exploitation requires network proximity but imposes no special user permissions. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, so public exploitation evidence is currently unknown. Nevertheless, the severity of credential theft warrants immediate attention, especially in environments where LDAPS traffic is exposed to untrusted hosts.
OpenCVE Enrichment