CVE-2026-12161 PUBLISHED

Assigner: DEVOLUTIONS
Reserved: 12.06.2026 Published: 15.06.2026 Updated: 15.06.2026

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.

Product Status

Vendor Devolutions
Product Remote Desktop Manager
Versions Default: unaffected
  • affected from 0 to 2026.2.7 (incl.)

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE