CVE-2026-8497

Summary

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.

Affected Software

VendorProductVersion RangeStatus
DevolutionsPassword Manager0 < 2026.2.2affected

Weaknesses

  • CWE-295: CWE-295 Improper certificate validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References