Impact
The vulnerability arises from improper certificate validation in the shared HTTP client used by Devolutions Server 2026.2.16 and earlier. An attacker who can position themselves in the network path can intercept outbound TLS traffic, insert a spoofed or self‑signed certificate, and modify the data exchanged between the server and its peers. This flaw allows a man‑in‑the‑middle attack that compromises confidentiality and integrity of data transmitted over transport layer security, potentially exposing sensitive business information or enabling further exploitation, such as credential theft or session hijacking.
Affected Systems
Vendors: Devolutions; Product: Devolutions Server. Affected versions include all releases up to and including 2026.2.16. Any installation of Devolutions Server 2026.2.16 or earlier is vulnerable.
Risk and Exploitability
With a CVSS score of 4.8, the flaw is considered moderate, but its impact remains a potential man‑in‑the‑middle attack that undermines TLS confidentiality and integrity. The EPSS score is very low at less than 1% (approximately 0.00093), indicating a small but non‑zero likelihood of exploitation. No public exploits are listed in KEV. The vulnerability requires an attacker to position themselves in the network path and present a spoofed or self‑signed certificate to the client; therefore, the risk is highest where synchronization and integration services are exposed to untrusted networks or where network segmentation is weak.
OpenCVE Enrichment