Impact
The vulnerability arises from improper certificate validation in the shared HTTP client used by Devolutions Server 2026.2.16 and earlier. An attacker who can position themselves in the network path can intercept outbound TLS traffic, insert a spoofed or self‑signed certificate, and modify the data exchanged between the server and its peers. This flaw allows a man‑in‑the‑middle attack that compromises confidentiality and integrity of data transmitted over transport layer security, potentially exposing sensitive business information or enabling further exploitation, such as credential theft or session hijacking.
Affected Systems
Vendors: Devolutions; Product: Devolutions Server. Affected versions include all releases up to and including 2026.2.16. Any installation of Devolutions Server 2026.2.16 or earlier is vulnerable.
Risk and Exploitability
The flaw carries a high severity due to its ability to break TLS security. The EPSS score is very low at less than 1% (approximately 0.00093), indicating a small but non‑zero likelihood of exploitation. The absence of an exploit flag in KEV indicates that no public exploits have yet been observed. However, the typical attack requires network proximity and the ability to present a certificate to the client; therefore, the risk is highest in environments where synchronization and integration services are exposed to untrusted networks or where network segmentation is weak.
OpenCVE Enrichment