← Back

CVE-2026-13372

nvd nist
Published: Jun 26, 2026Modified: Jun 29, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.

Affected (1)

1 product
Remote Desktop Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2026.2.5.0 to 2026.2.12.0

References (1)

Source: security@devolutions.net
Vendor Advisory

Timeline

No history available yet.