CVE-2026-13372 PUBLISHED

Assigner: DEVOLUTIONS
Reserved: 25.06.2026 Published: 26.06.2026 Updated: 26.06.2026

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.

Product Status

Vendor Devolutions
Product Remote Desktop Manager
Versions Default: unaffected
  • affected from 2026.2.5 to 2026.2.11 (excl.)

References

Problem Types

  • CWE-706 CWE