CVE-2026-12161
ANALYSIS PENDINGDevolutions Remote Desktop Manager < 2026.2.7 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Title source: ruleDescription
Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.
References (1)
Core 1
Core References
Details
CWE
CWE-78
Status
published
Products (1)
Devolutions/Remote Desktop Manager
< 2026.2.7
Published
Jun 16, 2026
Tracked Since
Jun 16, 2026