PT-2026-52892 · Devolutions · Remote Desktop Manager

CVE-2026-13372

·

Published

2026-06-26

·

Updated

2026-06-29

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devolutions Remote Desktop Manager versions 2026.2.5 through 2026.2.11
Description An issue exists in the custom PowerShell VPN editor where incorrect link resolution by display name allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context. This occurs through a display name collision with an existing VPN script link.
Recommendations Update Devolutions Remote Desktop Manager to a version later than 2026.2.11.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13372

Affected Products

Remote Desktop Manager