Executive brief
Devolutions Remote Desktop Manager, a tool used by IT professionals to manage remote connections and passwords, contains a security flaw in its social login autofill feature. An attacker could create a deceptive web entry that tricks the software into filling sensitive social login credentials into a fake website. This could lead to the theft of user credentials and unauthorized access to social media or service provider accounts.
Technical details
A vulnerability exists in Devolutions Remote Desktop Manager (up to version 2026.2.8.0) due to improper host validation within the social login autofill mechanism. The application fails to strictly verify the destination domain before populating stored credentials, allowing an attacker to use a lookalike domain to intercept sensitive login information. Exploitation requires the attacker to create a crafted web entry and necessitates user interaction to trigger the autofill action. This can result in the disclosure of stored social login credentials to an unauthorized third party. Users are advised to upgrade to a patched version.
Affected products
- Devolutions Remote Desktop Manager 2026.2.8.0 and earlier
Timeline
- 2026-06-12: advisory: Initial publication by Devolutions
- 2026-06-16: disclosed: CVE published to NVD