Executive brief
Devolutions Password Manager, a tool used to store and manage corporate credentials, contains a security flaw in how it handles encrypted connections to its central server on mobile and macOS devices. An attacker located on the same local network (such as a public Wi-Fi) could use a forged security certificate to intercept or modify sensitive data as it travels between the app and the server. This could lead to the exposure of managed passwords or other sensitive organizational information.
Technical details
A vulnerability classified as Improper Certificate Validation (CWE-295) exists in the Devolutions Server connection handling component of Devolutions Password Manager. The flaw affects the Android, iOS, and macOS versions of the application. An attacker positioned on the same adjacent network can perform a man-in-the-middle (MitM) attack by presenting a forged TLS certificate that the application fails to properly validate. Successful exploitation allows the attacker to intercept, read, or modify sensitive data transmitted between the client and the Devolutions Server. The issue is resolved in version 2026.2.2.0 and later.
Affected products
- Devolutions Password Manager 2026.2.1.0 and earlier
Timeline
- 2026-07-29: disclosed: Initial publication of advisory DEVO-2026-0027
- 2026-07-29: patched: Fix released in version 2026.2.2.0