MAIN MENU

Security & compliance

Upholding the highest standards to protect your data and ensure trust.

DEVO-2026-0021

Remote Desktop Manager is affected by an Incorrect link resolution by display name in PowerShell VPN editor vulnerability.

Affected Products

Remote Desktop Manager
2026.2.5 through 2026.2.11

Change Log

Initial publication - 2026-06-25

Incorrect link resolution by display name in PowerShell VPN editor

5.8 Medium - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.

CVE(s)

CVE-2026-13372

Remediation and Workarounds

Upgrade to Devolutions Remote Desktop Manager 2026.2.12.0 or higher.