PT-2026-80992 · Devolutions · Remote Desktop Manager
CVE-2026-78417
·
Published
2026-08-24
·
Updated
2026-08-28
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Devolutions Remote Desktop Manager versions prior to 2026.2.17.1
Devolutions Remote Desktop Manager versions prior to 2026.1.24.1
Description
Insufficient verification of data authenticity in the IronVNC client allows an on-path attacker to intercept and tamper with VNC sessions. This occurs due to the automatic acceptance of the server's RSA key during RSA-AES authentication, which is a process used to secure the communication channel between the client and the server.
Recommendations
Update to a version later than 2026.2.17.0.
Update to a version later than 2026.1.24.0.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Desktop Manager