CVE-2026-12161

ANALYSIS PENDING

Devolutions Remote Desktop Manager < 2026.2.7 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Title source: rule
STIX 2.1

Description

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.

References (1)

Core 1

Details

CWE
CWE-78
Status published
Products (1)
Devolutions/Remote Desktop Manager < 2026.2.7
Published Jun 16, 2026
Tracked Since Jun 16, 2026