Description
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
Published:
2026-09-15
Score:
n/a
EPSS:
n/a
KEV:
No
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0030/ |
|
History
Tue, 15 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate. | |
| Weaknesses | CWE-295 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-09-15T19:11:12.745Z
Reserved: 2026-09-02T12:53:37.050Z
Link: CVE-2026-84850
No data.
Status : Received
Published: 2026-09-15T19:17:44.183
Modified: 2026-09-15T19:17:44.183
Link: CVE-2026-84850
No data.
OpenCVE Enrichment
No data.
Weaknesses