CVE-2026-0747 Details
Description
Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing.
A vulnerability in the TeamViewer entry dashboard component of Devolutions Remote Desktop Manager versions 2025.3.24.0 through 2025.3.28.0 on Windows allows external observers to see passwords on screen. This issue arises from a flawed masking feature, which can expose sensitive information during physical observation or screen sharing.
Users are advised to upgrade to Devolutions Remote Desktop Manager version 2025.3.29.0 or higher.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0002/ | [email protected] | Broken LinkVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| devolutions remote desktop manager | >= 2025.3.24.0, < 2025.3.29.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 22, 2026 | Initial Analysis | [email protected] |
| Jan 8, 2026 | New CVE Received | [email protected] |
| Jan 8, 2026 | CVE Modified | CISA-ADP |