Improper Certificate Validation in PAM Propagation via WinRM Connections by Devolutions
CVE-2026-4434
8.1HIGH
What is CVE-2026-4434?
The vulnerability involves improper certificate validation in the PAM propagation through WinRM connections. This flaw could allow an attacker to execute a man-in-the-middle attack by exploiting disabled TLS certificate verification. Such security oversight may lead to unauthorized access and data breaches, compromising sensitive information and network integrity.
Affected Version(s)
Server 0 < 2026.1
