PT-2026-52892 · Devolutions · Remote Desktop Manager
CVE-2026-13372
·
Published
2026-06-26
·
Updated
2026-06-29
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Devolutions Remote Desktop Manager versions 2026.2.5 through 2026.2.11
Description
An issue exists in the custom PowerShell VPN editor where incorrect link resolution by display name allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context. This occurs through a display name collision with an existing VPN script link.
Recommendations
Update Devolutions Remote Desktop Manager to a version later than 2026.2.11.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Desktop Manager