{"id":"CVE-2026-8497","title":"Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive informa…","summary":"Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive informa…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-295"],"vendor":"devolutions","product":"password_manager","affected":["password_manager < 2026.2.2.0"],"patched":["password_manager 2026.2.2.0"],"published":"2026-07-29","updated":"2026-08-21","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8497","references":[{"url":"https://devolutions.net/security/advisories/DEVO-2026-0027/","label":"security@devolutions.net"}],"tags":["nvd"],"epss":0.00082,"epssPercentile":0.00267,"ingestedAt":"2026-08-22T13:32:35.737Z","slug":"CVE-2026-8497","body":"## Overview\n\nImproper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.\n\n## Affected\n\n- `password_manager < 2026.2.2.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `password_manager 2026.2.2.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}