Executive brief
Devolutions Remote Desktop Manager, a tool used by IT teams to manage remote server connections, is vulnerable to a command injection flaw. An authorized user with the ability to edit shared connection settings could trick the system into running unauthorized commands on a remote server. This could lead to a full compromise of the remote host using saved administrative credentials.
Technical details
An OS command injection vulnerability (CWE-78) exists in the SSH Elevate Shell feature of Devolutions Remote Desktop Manager due to improper input validation. An authenticated attacker with permissions to create or modify shared SSH entries can craft a malicious 'alternate username' field. When a victim interacts with the 'Elevate Shell' action using stored elevation credentials, the injected commands are executed on the remote SSH host. This requires network reachability to the remote host and specific user interaction to trigger the elevation process. The issue is addressed in versions newer than 2026.2.8.0.
Affected products
- Devolutions Remote Desktop Manager 2026.2.8.0 and earlier
Timeline
- 2026-06-12: advisory: Initial publication by Devolutions
- 2026-06-16: disclosed: NVD publication date