CVE-2026-13372

HIGH

Devolutions Remote Desktop Manager < 2026.2.11 - Use of Incorrectly-Resolved Name or Reference

Title source: rule
STIX 2.1

Description

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0028
EPSS Percentile 20.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-706
Status published
Products (2)
Devolutions/Remote Desktop Manager 2026.2.5 - 2026.2.11
devolutions/remote_desktop_manager 2026.2.5.0 - 2026.2.12.0
Published Jun 26, 2026
Tracked Since Jun 27, 2026