CVE-2026-12161

Summary

Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.

This affects  : 

  • Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0

  • Remote Desktop Manager 2026.1.23.0 and earlier

Affected Software

VendorProductVersion RangeStatus
DevolutionsRemote Desktop Manager2026.2.5.0 <= 2026.2.7affected
DevolutionsRemote Desktop Manager0 <= 2026.1.23.0affected

Weaknesses

  • CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References