CVE-2026-4396

EUVD-2026-12950
Improper certificate validation in Devolutions Hub Reporting Service 
2025.3.1.1 and earlier allows a network attacker to perform a 
man-in-the-middle attack via disabled TLS certificate verification.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
devolutionshub_reporting_service
𝑥
< 2026.1.1.0
𝑥
= Vulnerable software versions