What is CVE-2026-8497?
A vulnerability in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS involves improper TLS certificate validation during server connection. This allows an adjacent-network attacker to intercept and modify sensitive information using a forged TLS certificate. Users should update to the latest patched version immediately.
Azərbaycanca: Devolutions Password Manager-in 2026.2.1.0 və daha əvvəlki versiyalarında server əlaqəsi zamanı TLS sertifikatının düzgün yoxlanılmaması zəifliyi aşkar edilib. Android, iOS və macOS platformalarına təsir edən bu qüsur, yaxın şəbəkədəki təcavüzkara saxta TLS sertifikatı vasitəsilə həssas məlumatları ələ keçirməyə və dəyişdirməyə imkan verir. İstifadəçilər dərhal ən son versiyaya yeniləmə etməlidir.
Related CVEs
link basis: shared vendor: Devolutions
FAQ2
Which platforms are affected by the CVE-2026-8497 vulnerability in Devolutions Password Manager?
This vulnerability affects Devolutions Password Manager on Android, iOS, and macOS platforms.
What can an attacker achieve by exploiting CVE-2026-8497?
An adjacent-network attacker can intercept and modify sensitive information using a forged TLS certificate.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.