CVE-2026-12161
Description
Devolutions Remote Desktop Manager 2026.2.7 allows authenticated SSH entry editors to execute arbitrary commands via crafted alternate username in Elevate Shell.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Devolutions Remote Desktop Manager 2026.2.7 allows authenticated SSH entry editors to execute arbitrary commands via crafted alternate username in Elevate Shell.
Vulnerability
Improper input validation in the SSH Elevate Shell feature of Devolutions Remote Desktop Manager (RDM) version 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host. The bug is triggered by entering a crafted alternate username in the SSH entry and subsequently using the Elevate Shell action, which passes the untrusted input to the stored elevation credentials without sanitization.
Exploitation
An attacker needs valid authentication to RDM and the permission to create or modify a shared SSH entry. The steps are: create or edit a shared SSH entry, set an alternate username containing shell metacharacters or command injection syntax, save the entry, and then have a target user (or themselves) interact with the Elevate Shell action. No additional network access beyond what is normal for SSH management is required.
Impact
On success, the attacker achieves arbitrary command execution on the remote SSH host in the context of the stored elevation credentials. This can lead to full compromise of the remote host, including data exfiltration, lateral movement, or privilege escalation within the target environment [1].
Mitigation
Devolutions released a security advisory (DEVO-2026-0018) [1] addressing this issue. Users should upgrade to a patched version of Remote Desktop Manager as soon as possible. If an immediate upgrade is not possible, restrict permissions for creating or modifying shared SSH entries to trusted users only and avoid using stored elevation credentials with shared SSH entries until the fix is applied.
AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: =2026.2.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.