Improper Certificate Validation in Devolutions Hub Reporting Service
CVE-2026-4396
8.3HIGH
What is CVE-2026-4396?
The Devolutions Hub Reporting Service is vulnerable due to improper certificate validation in versions 2025.3.1.1 and earlier. This allows network attackers to exploit disabled TLS certificate verification, potentially leading to man-in-the-middle attacks. Attackers could intercept data or inject malicious content without detection. Users are advised to update to the latest versions to mitigate this risk and ensure secure communications.
Affected Version(s)
Hub Reporting Service 0 <= 2025.3.1.1
