CVE-2026-4396

HIGH

Devolutions Hub Reporting Service <=2025.3.1.1 - MITM

Title source: llm
STIX 2.1

Description

Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

Scores

CVSS v3 8.1
EPSS 0.0004
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (2)
Devolutions/Hub Reporting Service < 2025.3.1.1
devolutions/hub_reporting_service < 2026.1.1.0
Published Mar 18, 2026
Tracked Since Mar 19, 2026