VYPR
Unrated severityNVD Advisory· Published Jun 16, 2026

CVE-2026-12161

CVE-2026-12161

Description

Devolutions Remote Desktop Manager 2026.2.7 allows authenticated SSH entry editors to execute arbitrary commands via crafted alternate username in Elevate Shell.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Devolutions Remote Desktop Manager 2026.2.7 allows authenticated SSH entry editors to execute arbitrary commands via crafted alternate username in Elevate Shell.

Vulnerability

Improper input validation in the SSH Elevate Shell feature of Devolutions Remote Desktop Manager (RDM) version 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host. The bug is triggered by entering a crafted alternate username in the SSH entry and subsequently using the Elevate Shell action, which passes the untrusted input to the stored elevation credentials without sanitization.

Exploitation

An attacker needs valid authentication to RDM and the permission to create or modify a shared SSH entry. The steps are: create or edit a shared SSH entry, set an alternate username containing shell metacharacters or command injection syntax, save the entry, and then have a target user (or themselves) interact with the Elevate Shell action. No additional network access beyond what is normal for SSH management is required.

Impact

On success, the attacker achieves arbitrary command execution on the remote SSH host in the context of the stored elevation credentials. This can lead to full compromise of the remote host, including data exfiltration, lateral movement, or privilege escalation within the target environment [1].

Mitigation

Devolutions released a security advisory (DEVO-2026-0018) [1] addressing this issue. Users should upgrade to a patched version of Remote Desktop Manager as soon as possible. If an immediate upgrade is not possible, restrict permissions for creating or modifying shared SSH entries to trusted users only and avoid using stored elevation credentials with shared SSH entries until the fix is applied.

References
  1. advisories

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.