Description
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
Published: 2026-09-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Man-in-the-Middle/TLS Interception
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper certificate validation in the shared HTTP client used by Devolutions Server 2026.2.16 and earlier. An attacker who can position themselves in the network path can intercept outbound TLS traffic, insert a spoofed or self‑signed certificate, and modify the data exchanged between the server and its peers. This flaw allows a man‑in‑the‑middle attack that compromises confidentiality and integrity of data transmitted over transport layer security, potentially exposing sensitive business information or enabling further exploitation, such as credential theft or session hijacking.

Affected Systems

Vendors: Devolutions; Product: Devolutions Server. Affected versions include all releases up to and including 2026.2.16. Any installation of Devolutions Server 2026.2.16 or earlier is vulnerable.

Risk and Exploitability

The flaw carries a high severity due to its ability to break TLS security. The EPSS score is very low at less than 1% (approximately 0.00093), indicating a small but non‑zero likelihood of exploitation. The absence of an exploit flag in KEV indicates that no public exploits have yet been observed. However, the typical attack requires network proximity and the ability to present a certificate to the client; therefore, the risk is highest in environments where synchronization and integration services are exposed to untrusted networks or where network segmentation is weak.

Generated by OpenCVE AI on September 17, 2026 at 07:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Devolutions Server to any version newer than 2026.2. that the shared HTTP client or server settings to ensuring strict certificate chain verification.
  • Restrict exposure of synchronization and integration endpoints by placing them behind a firewall or VPN, limiting the ability of attackers to position themselves in the network.
  • Regularly review TLS logs and monitor for certificate‑ early.

Generated by OpenCVE AI on September 17, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Enables TLS Interception in Devolutions Server

Wed, 16 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation Enables TLS Interception in Devolutions Server

Tue, 15 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Devolutions
Devolutions server
Vendors & Products Devolutions
Devolutions server

Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
Weaknesses CWE-295
References

Subscriptions

Devolutions Server
cve-icon MITRE

Status: PUBLISHED

Assigner: DEVOLUTIONS

Published:

Updated: 2026-09-15T19:11:12.745Z

Reserved: 2026-09-02T12:53:37.050Z

Link: CVE-2026-84850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:44.183

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-84850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T07:45:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation