Description
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
Published: 2026-09-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Man-in-the-Middle/TLS Interception
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper certificate validation in the shared HTTP client used by Devolutions Server 2026.2.16 and earlier. An attacker who can position themselves in the network path can intercept outbound TLS traffic, insert a spoofed or self‑signed certificate, and modify the data exchanged between the server and its peers. This flaw allows a man‑in‑the‑middle attack that compromises confidentiality and integrity of data transmitted over transport layer security, potentially exposing sensitive business information or enabling further exploitation, such as credential theft or session hijacking.

Affected Systems

Vendors: Devolutions; Product: Devolutions Server. Affected versions include all releases up to and including 2026.2.16. Any installation of Devolutions Server 2026.2.16 or earlier is vulnerable.

Risk and Exploitability

With a CVSS score of 4.8, the flaw is considered moderate, but its impact remains a potential man‑in‑the‑middle attack that undermines TLS confidentiality and integrity. The EPSS score is very low at less than 1% (approximately 0.00093), indicating a small but non‑zero likelihood of exploitation. No public exploits are listed in KEV. The vulnerability requires an attacker to position themselves in the network path and present a spoofed or self‑signed certificate to the client; therefore, the risk is highest where synchronization and integration services are exposed to untrusted networks or where network segmentation is weak.

Generated by OpenCVE AI on September 20, 2026 at 13:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Devolutions Server to any version newer than 2026.2.16 that includes the HTTP client certificate validation fix.
  • Restrict exposure of synchronization and integration endpoints by placing them behind a firewall or VPN, limiting the ability of attackers to position themselves in the network.
  • Regularly review TLS logs and monitor for certificate anomalies.

Generated by OpenCVE AI on September 20, 2026 at 13:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Improper HTTP Client Certificate Validation in Devolutions Server 2026.2.16 and Earlier

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Enables TLS Interception in Devolutions Server

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Enables TLS Interception in Devolutions Server

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
Weaknesses CWE-295
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-09-20T00:38:07.754Z

Reserved: 2026-09-02T12:53:37.050Z

Link: CVE-2026-84850

cve-icon Vulnrichment

Updated: 2026-09-20T00:38:00.612Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:44.183

Modified: 2026-09-20T01:16:30.577

Link: CVE-2026-84850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:15:14Z

Weaknesses
  • CWE-295

    Improper Certificate Validation