Improper Certificate Validation in Devolutions Hub Reporting Service
CVE-2026-4396

8.3HIGH

Key Information:

Vendor
CVE Published:
18 March 2026

What is CVE-2026-4396?

The Devolutions Hub Reporting Service is vulnerable due to improper certificate validation in versions 2025.3.1.1 and earlier. This allows network attackers to exploit disabled TLS certificate verification, potentially leading to man-in-the-middle attacks. Attackers could intercept data or inject malicious content without detection. Users are advised to update to the latest versions to mitigate this risk and ensure secure communications.

Affected Version(s)

Hub Reporting Service 0 <= 2025.3.1.1

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.