Junglewise Threat Intelligence

CVE-2026-12161: Devolutions Remote Desktop Manager command injection in SSH Elevate Shell

CVE-2026-12161 · Severity: info · CVSS 5.2 · Published 2026-06-16

Technologies: Devolutions Remote Desktop Manager. Vendors: Devolutions.

Executive brief

Devolutions Remote Desktop Manager, a tool used by IT teams to manage remote server connections, is vulnerable to a command injection flaw. An authorized user with the ability to edit shared connection settings could trick the system into running unauthorized commands on a remote server. This could lead to a full compromise of the remote host using saved administrative credentials.

Technical details

An OS command injection vulnerability (CWE-78) exists in the SSH Elevate Shell feature of Devolutions Remote Desktop Manager due to improper input validation. An authenticated attacker with permissions to create or modify shared SSH entries can craft a malicious 'alternate username' field. When a victim interacts with the 'Elevate Shell' action using stored elevation credentials, the injected commands are executed on the remote SSH host. This requires network reachability to the remote host and specific user interaction to trigger the elevation process. The issue is addressed in versions newer than 2026.2.8.0.

Affected products

  • Devolutions Remote Desktop Manager 2026.2.8.0 and earlier

Timeline

  • 2026-06-12: advisory: Initial publication by Devolutions
  • 2026-06-16: disclosed: NVD publication date

References

Related threats