CVE-2026-13372
Devolutions Remote Desktop Manager PowerShell Script Execution via Display Name Collision
Description
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.
INFO
Published Date :
June 26, 2026, 6:22 p.m.
Last Modified :
June 26, 2026, 6:22 p.m.
Remotely Exploit :
No
Source :
DEVOLUTIONS
Solution
- Update Devolutions Remote Desktop Manager to the latest version.
- Apply the vendor-provided patch for the vulnerability.
- Review and restrict write access to shared workspaces.
- Remove any unnecessary VPN script links.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-13372 vulnerability anywhere in the article.