Junglewise Threat Intelligence

CVE-2026-13327: Devolutions Server improper LDAPS certificate validation

CVE-2026-13327 · Severity: high · CVSS 8.3 · Published 2026-09-15

Executive brief

Devolutions Server is a centralized platform for managing remote connections and privileged access to IT infrastructure. The application fails to properly validate SSL/TLS certificates when connecting to Active Directory via LDAPS, allowing an attacker positioned on the network to intercept and steal Active Directory administrative credentials by presenting a forged domain controller certificate.

Technical details

This vulnerability stems from improper certificate validation in LDAPS (LDAP over SSL) connections to Active Directory. An attacker on the network can perform a man-in-the-middle (MITM) attack by spoofing a domain controller's certificate without proper validation being performed. The attack requires network positioning between the affected system and Active Directory, but no authentication or user interaction. Successful exploitation allows credential interception for privileged directory service accounts. The vulnerability affects Devolutions Server version 2026.2.16 and earlier; patches should be available from Devolutions.

Affected products

  • Devolutions Server 2026.2.16 and earlier

Timeline

  • 2026-09-15: disclosed

References