CVE-2026-84850

Summary

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.

Affected Software

VendorProductVersion RangeStatus
DevolutionsServer0 <= 2026.2.16affected

Weaknesses

  • CWE-295: CWE-295 Improper certificate validation

References