PT-2026-80992 · Devolutions · Remote Desktop Manager

CVE-2026-78417

·

Published

2026-08-24

·

Updated

2026-08-28

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Devolutions Remote Desktop Manager versions prior to 2026.2.17.1 Devolutions Remote Desktop Manager versions prior to 2026.1.24.1
Description Insufficient verification of data authenticity in the IronVNC client allows an on-path attacker to intercept and tamper with VNC sessions. This occurs due to the automatic acceptance of the server's RSA key during RSA-AES authentication, which is a process used to secure the communication channel between the client and the server.
Recommendations Update to a version later than 2026.2.17.0. Update to a version later than 2026.1.24.0.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78417

Affected Products

Remote Desktop Manager