HIGHVulnerability

CVE-2026-8497

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.

Properties

severity
HIGH
score
7.4
cve_id
CVE-2026-8497
vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
published_at
2026-07-29T18:16:58.787
last_modified
2026-08-21T15:07:40.067

Related Entities (6)

AFFECTS_PRODUCT (4)

[Product]
[Product]
[Product]
[Product]

HAS_WEAKNESS (1)

[Weakness]Improper Certificate Validation

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-8497 — Ninja Signal Threat Intelligence | Ninja Signal