Improper Certificate Validation in Devolutions Server by Devolutions
CVE-2026-84850
Currently unrated
What is CVE-2026-84850?
A vulnerability exists in Devolutions Server due to improper certificate validation within its shared HTTP client. This flaw allows a network-positioned attacker to create conditions for intercepting and tampering with outbound TLS connections utilizing spoofed or self-signed certificates. This could lead to a serious compromise of sensitive data in transit. Users of affected versions should consider evaluating their network's security posture to mitigate potential risks.
Affected Version(s)
Server 0 <= 2026.2.16
