LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4434 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 23, 2026

PAM propagation WinRM - Man-in-the-Middle

Published: March 20, 2026Updated: March 23, 2026Remote Exploitable

Overview

PAM propagation WinRM connections contain a man-in-the-middle vulnerability caused by improper certificate validation due to disabled TLS certificate verification, letting network attackers intercept and modify communications, exploit requires network access.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 1.0%(Probability of exploitation in next 30 days)

Impact

Network attackers can intercept and modify communications, potentially stealing sensitive data or injecting malicious content.

Mitigation

Enable proper TLS certificate validation or update to a version with correct certificate verification.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-4434 - High (8.1) Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4434/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-4434 - High (8.1) Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4434/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-4434
Severity
High
CVSS Score
8.1
Type
man_in_the_middle
Status
unconfirmed
EPSS
1.0%
Social Posts
2

CWE

  • CWE-295

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

1.0%Probability of exploitation in the next 30 days