CVE-2026-13372 Details
Description
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.
A vulnerability exists in Devolutions Remote Desktop Manager versions 2026.2.5 through 2026.2.11, due to incorrect link resolution by display name in the custom PowerShell VPN editor. This flaw allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context. The exploitation relies on creating a display name collision with an existing VPN script link.
Users are advised to upgrade to Devolutions Remote Desktop Manager version 2026.2.12.0 or higher.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0021/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-706 | Use of Incorrectly-Resolved Name or Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| devolutions remote desktop manager | >= 2026.2.5.0, <= 2026.2.12.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |