CVE-2026-12161

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
16/06/2026
Last modified:
20/07/2026

Description

Improper input validation in the SSH Elevate Shell feature allows an authenticated user<br /> with permission to create or modify a shared SSH entry to execute <br /> arbitrary commands on a remote SSH host using stored elevation <br /> credentials via a crafted alternate username and user interaction with <br /> the Elevate Shell action.<br /> <br /> This affects  : <br /> - Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0<br /> <br /> - Remote Desktop Manager 2026.1.23.0 and earlier

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:devolutions:remote_desktop_manager:*:*:*:*:*:windows:*:* 2026.2.8.0 (excluding)


References to Advisories, Solutions, and Tools