CVE-2026-4396 PUBLISHED

Assigner: DEVOLUTIONS
Reserved: 18.03.2026 Published: 18.03.2026 Updated: 18.03.2026

Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

Product Status

Vendor Devolutions
Product Hub Reporting Service
Versions Default: unaffected
  • affected from 0 to 2025.3.1.1 (incl.)

References

Problem Types

  • CWE-295 Improper certificate validation CWE