CVE-2026-13372

Published Jun 26, 2026

Last updated a month ago

Overview

Description
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.
Source
security@devolutions.net
NVD status
Analyzed
Products
remote_desktop_manager

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.2
Impact score
5.9
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@devolutions.net
CWE-706

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.