Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://devolutions.net/security/advisories/DEVO-2026-0021/ |
|
History
Fri, 26 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary PowerShell Execution via Display Name Collision in Remote Desktop Manager |
Fri, 26 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link. | |
| Weaknesses | CWE-706 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: DEVOLUTIONS
Published:
Updated: 2026-06-26T19:25:32.593Z
Reserved: 2026-06-25T19:55:53.064Z
Link: CVE-2026-13372
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T20:30:06Z
Weaknesses