Junglewise Threat Intelligence

CVE-2026-78417: Devolutions Remote Desktop Manager VNC man-in-the-middle via weak key verification

CVE-2026-78417 · Severity: medium · CVSS 4.3 · Published 2026-08-24

Technologies: Devolutions Remote Desktop Manager. Vendors: Devolutions.

Executive brief

Devolutions Remote Desktop Manager is a widely-used enterprise tool for managing remote desktop and VNC connections. A flaw in the IronVNC client component allows an attacker positioned on the network path to intercept and tamper with VNC sessions by automatically accepting unverified RSA keys, potentially exposing remote desktop sessions to eavesdropping and manipulation without user awareness.

Technical details

The vulnerability exists in the IronVNC client used by Remote Desktop Manager, which fails to properly verify the authenticity of the VNC server's RSA key during RSA-AES authentication. An on-path attacker (network-positioned) can intercept the TLS/RSA handshake and substitute their own key, which the client automatically accepts without prompting or validating the certificate fingerprint. This allows the attacker to establish a man-in-the-middle position between the client and legitimate VNC server, gaining the ability to read and modify all encrypted session traffic. No user interaction beyond initiating a normal VNC connection is required. The issue affects Remote Desktop Manager versions 2026.2.17.0 and earlier, and 2026.1.24.0 and earlier; patches are available from Devolutions.

Affected products

  • Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: advisory: DEVO-2026-0029

References

Related threats