PT-2026-26149 · Devolutions · Devolutions Hub Reporting Service

Published

2026-03-18

·

Updated

2026-03-18

·

CVE-2026-4396

CVSS v3.1

8.3

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Devolutions Hub Reporting Service versions 2025.3.1.1 and earlier
Description A flaw exists in the certificate validation process within the Devolutions Hub Reporting Service. Specifically, TLS certificate verification is disabled, which enables a network attacker to conduct a man-in-the-middle attack.
Recommendations Versions prior to 2025.3.1.1 should be updated.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2026-4396

Affected Products

Devolutions Hub Reporting Service