Executive brief
Devolutions Server is a centralized platform for managing remote connections and privileged access across organizations. An attacker positioned on the network can intercept and modify outbound connections made by the server's synchronization and integration features by presenting a spoofed or self-signed TLS certificate, potentially compromising the integrity of data exchanged with external systems.
Technical details
The vulnerability is an improper certificate validation flaw in the shared HTTP client library used by Devolutions Server's synchronization and integration features. The HTTP client fails to properly validate TLS certificates when establishing outbound connections, allowing a network-positioned attacker to perform man-in-the-middle attacks using spoofed or self-signed certificates. This affects versions 2026.2.16 and earlier. The attack requires network proximity to intercept traffic but does not require authentication or user interaction. An attacker can intercept and modify data transmitted during synchronization and integration operations, potentially compromising credential stores, configuration data, or integration endpoints.
Affected products
- Devolutions Server 2026.2.16 and earlier
Timeline
- 2026-09-15: disclosed