Junglewise Threat Intelligence

CVE-2026-2590: Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Mana

CVE-2026-2590 · Severity: critical · CVSS 9.8 · Published 2026-03-03

Technologies: Devolutions Server, Devolutions Remote Desktop Manager. Vendors: Devolutions.

Executive brief

Devolutions Remote Desktop Manager, a tool used by IT teams to manage remote connections and credentials, contains a flaw that fails to enforce security policies regarding password storage. This allows users to save credentials in shared vaults even when administrators have explicitly disabled that feature. This could lead to the unauthorized persistence and potential exposure of sensitive login information to other users within the organization.

Technical details

A vulnerability in the connection entry component of Devolutions Remote Desktop Manager (and Devolutions Server) results from improper enforcement of the 'Disable password saving in vaults' security setting. Authenticated users can bypass this restriction by creating or editing specific connection types, allowing them to save and persist credentials within vault entries. This flaw can lead to unauthorized credential disclosure to other users who have access to the same vault. The issue is addressed in versions newer than 2025.3.30 for Remote Desktop Manager and 2025.3.15.0 for Devolutions Server.

Affected products

  • Devolutions Remote Desktop Manager 2025.3.30 and earlier
  • Devolutions Devolutions Server 2025.3.15.0 and earlier

Timeline

  • 2026-03-03: disclosed: Initial publication of the advisory.
  • 2026-03-03: advisory: Vendor advisory DEVO-2026-0005 published.

References

Related threats