LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-12161

devolutions · remote desktop manager

Published
CVSS8.8
Severityhigh
WeaknessCWE-78
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. This affects  :  - Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0 - Remote Desktop Manager 2026.1.23.0 and earlier

References

← Back to the CVE Tracker

Our coverage of CVE-2026-12161

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-12161.