CVE-2026-8497
EUVD-2026-5042229.07.2026, 18:16
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| devolutions | password_manager | 𝑥 < 2026.2.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration