CVE-2026-4396

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
18/03/2026
Last modified:
30/03/2026

Description

Improper certificate validation in Devolutions Hub Reporting Service <br /> 2025.3.1.1 and earlier allows a network attacker to perform a <br /> man-in-the-middle attack via disabled TLS certificate verification.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:devolutions:hub_reporting_service:*:*:*:*:*:*:*:* 2026.1.1.0 (excluding)


References to Advisories, Solutions, and Tools